IP Library Granted Patent US 12,464,362
Granted Patent B2
US 12,464,362 · App. 18/252,183 · Granted Nov 4, 2025

Subscription onboarding using a verified digital identity

Inventors: Sheeba Backia Mary Baskaran (Friedrichsdorf, DE); Apostolis Salkintzis (Athens, GR); Andreas Kunz (Ladenburg, DE); Genadi Velev (Darmstadt, DE); Roozbeh Atarius (La Jolla, CA); Ishan Vaishnavi (Munich, DE); Emmanouil Pateromichelakis (Viersen, DE); Dimitrios Karampatsis (Ruislip, GB)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04W12/72H04L9/3247H04L9/3297H04W12/75
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,362
App. No.
18/252,183
Granted
Nov 4, 2025
Kind
B2
Abstract

Apparatuses, methods, and systems are disclosed for Digital Identifier-based subscription onboarding. One apparatus includes a memory coupled to a processor, the memory storing instructions executable by the processor to control the apparatus to acquire a Digital Identifier (“DIG-ID”) comprising a verifiably secure identity, and to generate a digital signature of the DIG-ID and a timestamp using a private key. The instructions are executable by the processor to control the apparatus to send a first request to a mobile communication network and to receive a response containing an onboarding authentication success indication and a verified DIG-ID, the first request including the DIG-ID, the timestamp and the digital signature. The instructions are executable by the processor to establish a provisioning connection to the mobile communication network and to receive a subscription credential and/or a user subscription profile via the provisioning connection.

Claims (58)

1 . A method of a user equipment (“UE”), the method comprising:

acquiring a digital identifier (“DIG-ID”) comprising a verifiably secure identity;

generating a digital signature of the DIG-ID and a timestamp using a private key;

sending a first request to a mobile communication network, the first request including the DIG-ID, the timestamp, and the generated digital signature;

receiving an onboarding authentication success indication and a verified DIG-ID;

establishing a provisioning connection to the mobile communication network; and

receiving at least one of a subscription credential and a user subscription profile via the provisioning connection.

2 . The method of claim 1 ,

wherein the first request contains a subscription unique onboarding identifier (“SUOI”), the SUOI containing the DIG-ID, the timestamp and the digital signature, wherein the SUOI further includes one or more of: a DIG-ID type, a service provider identifier, identity (“ID”) service provider domain information and trust service provider domain information, wherein the digital signature is generated using the SUOI,

wherein the SUOI further includes a message authentication code (“MAC”) of SUOI, public key of a user, and a public key identifier corresponding to a service provider identifier identified by the ID service provider domain information or the trust service provider domain information, if the DIG-ID is protected using a shared secret encryption key.

3 . The method of claim 1 , wherein the first request comprises a registration request that initiates a registration procedure with the mobile communication network, wherein the subscription credential or the user subscription profile is received by the UE in an onboard container over a non-access stratum (“NAS”) or a control plane message after a successful DIG-ID based user authentication or onboard root key-based security set up during the registration procedure.

4 . The method of claim 1 , wherein the first request comprises an onboarding request container, wherein the subscription credential or the user subscription profile is received by the UE in an onboarding response or in a user plane message after a successful DIG-ID based user authentication or onboard root key-based security set up during an onboarding and provisioning procedure.

5 . The method of claim 1 , wherein the DIG-ID comprises at least one of: a decentralized identifier (“DID”), a self-sovereign identifier (“SSI”), and a digital onboarding identifier (“DOID”), wherein acquiring the DIG-ID comprises purchasing a subscription associated with the mobile communication network or generating the DIG-ID at the UE.

6 . The method of claim 1 ,

wherein receiving subscription credentials or the user subscription profile comprises receiving a protected onboarding container from an access and mobility management function (“AMF”) in the mobile communication network,

wherein the protected onboarding container is received within a non-access stratum (“NAS”) message or user plane message that is protected using an encryption key and integrity key derived from a security key based on onboard root key,

wherein the NAS message includes onboarding assistance information (“OAI”), a nonce and a message authentication code (“MAC”).

7 . The method of claim 6 , further comprising:

deriving an onboard root key using a shared secret key and a successfully verified DIG-ID;

using the onboard root key as an authentication server function (“AUSF”) key;

deriving at least one security key using the onboard root key and using at least one of: the nonce, a plublic land mobile network (“PLMN”) identifier, and a network identifier;

using the at least one security key as a security anchor key and setting up security with the mobile communication network or using the at least one security key to derive an onboard confidentiality key to decrypt a protected onboard container and an onboard integrity key to verify the MAC of the NAS message providing the protected onboard container;

verifying the MAC of the NAS message based on the OAI containing onboard result with ‘success indication’ and one or more security algorithm identifiers; and

decrypting and storing the received subscription credentials or the user subscription profile in response to successfully verifying the MAC.

8 . A method of a network function in a mobile communication network, the method comprising:

receiving a first request message comprising a digital identifier (“DIG-ID”) of a user equipment (“UE”), a timestamp and a digital signature, the DIG-ID comprising a verifiably secure identity;

identifying a trust service provider based on the DIG-ID;

sending a verification request to the trust service provider, the verification request containing the DIG-ID, the timestamp, the digital signature, a minimum data set request, and a security key request;

receiving a verified DIG-ID, a verification result, a DIG-ID lifetime, minimum data set (“MDS”) information and an onboard root key from the trust service provider in response to successful verification of the DIG-ID; and

invoking subscription provisioning of the UE based on the MDS information, wherein the subscription provisioning is protected using the onboard root key.

9 . The method of claim 8 ,

wherein the MDS information comprises at least user information,

wherein invoking subscription provisioning of the UE based on the MDS information comprises invoking a temporary subscription credential provisioning in response to the MDS information only containing user information,

wherein invoking subscription provisioning of the UE based on the MDS information comprises invoking an actual user subscription profile provisioning in response to the MDS information containing user information and one or more of subscription purchase information, subscription service related information, subscription validity or a network resource for subscription provisioning.

10 . The method of claim 8 , further comprising:

generating a nonce;

deriving one or more security keys using the onboard root key and at least one of:

the nonce, a public land mobile network (“PLMN”) identifier, and a network identifier;

using the one security key to derive onboard security keys;

generating a plain text or protected onboarding container, and an OAI for the UE, the protected onboarding container being protected using at least one of the derived security keys; and

storing the verified DIG-ID, a verification result, a DIG-ID lifetime, the MDS information, and the onboard root key in a data management function (“DMF”) or a unified data management and unified data repository (“UDM/UDR”) of the mobile communication network.

11 . The method of claim 10 , further comprising fetching a default subscription credential for the DIG-ID from the DMF or UDM/UDR and deriving one or more onboard security keys, wherein the default subscription credential and the one or more onboard security keys are provided to a second network function that is one of: an access and mobility management function (“AMP”) and a security anchor function (“SEAF”).

12 . The method of claim 11 , further using the received onboard root key as an authentication server function (“AUSF”) key and providing the one security key as security anchor key to the AMF or SEAF to set up security with the UE for provisioning connection.

13 . The method of claim 10 ,

wherein confidentiality protection and integrity protection is applied to the protected onboarding container using an encryption key and an integrity key derived from the one or more onboard security key in response to receiving the default subscription credential in an unprotected onboarding container,

wherein the subscription provisioning of the UE comprises a non-access stratum (“NAS”) message that is confidentiality and integrity protected or contains the protected onboarding container, onboard assistance information, a nonce, and a message authentication code (“MAC”).

14 . The method of claim 13 ,

wherein the protected onboarding container includes a subscription credential, a secret long-term key (K), authentication and key agreement (“AKA”) credentials, and slice information, and

wherein the subscription credential comprises a subscription unique permanent identifier, wherein the protected onboarding container further includes network access information and additional subscription information.

15 . The method of claim 8 , wherein the first request contains a subscription unique onboarding identifier (“SUOI”), the SUOI containing the DIG-ID, the timestamp and the digital signature, wherein the SUOI further includes one or more of: a DIG-ID type, a service provider identifier, identity (“ID”) service provider domain information and trust service provider domain information, wherein the digital signature is generated using the SUOI.

16 . The method of claim 15 , wherein the SUOI further includes a message authentication code (“MAC”) of SUOI, public key of a user, and a public key identifier corresponding to a service provider identifier by the ID service provider domain information or the trust service provider domain information, if the DIG-ID is protected using a shared secret encryption key.

17 . The method of claim 8 , wherein the first request comprises an authentication request that initiates an authentication procedure with the mobile communication network, wherein subscription credentials or a user subscription profile are provisioned to the UE after a successful DIG-ID based user authentication or onboard root key based security set up in an onboard container over a non-access stratum (“NAS”) or a control plane message during a registration procedure.

18 . The method of claim 8 , wherein the first request comprises an onboarding request, wherein a subscription credential or a user subscription profile is provisioned to the UE in an onboarding response or in a user plane message during an onboarding and provisioning procedure.

19 . The method of claim 8 ,

wherein the DIG-ID is linked to verifiable credentials of a user that are stored on a trusted and decentralized platform or DIG-ID infrastructure associated with the trust service provider or ID service provider;

wherein the DIG-ID comprises at least one of: a decentralized identifier (“DID”), a self-sovereign identifier (“SSI”), the verifiably secure identity, and a digital onboarding identifier (“DOID”);

wherein the DIG-ID is used to perform user authentication during onboarding and subscription credentials provisioning to the UE.

20 . The method of claim 19 , wherein the DIG-ID is contained within a username portion of a network access identifier (“NAI”), the NAI comprising the DIG-ID and at least one of: a timestamp, a digital signature, key related information, trust service provider domain information or identity service provider domain information, wherein the NAI has a form <username@realm>.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2023
From: BASKARAN, SHEEBA BACKIA MARY; SALKINTZIS, APOSTOLIS; KUNZ, ANDREAS; VELEV, GENADI; ATARIUS, ROOZBEH; VAISHNAVI, ISHAN; PATEROMICHELAKIS, EMMANOUIL; KARAMPATSIS, DIMITRIOS
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 063777/0937 →
Continuity (1)
Related Publication 20230413060A1 · Dec 21, 2023
References Cited (22)
US 8555361B2 · Nakhjiri et al. · 2013 [cited by examiner]
US 8910241B2 · Pollutro · 2014 [cited by examiner]
US 9853977B1 · Laucius · 2017 [cited by examiner]
US 10743176B1 · Khan et al. · 2020 [cited by applicant]
US 20150032655A1 · Said · 2015 [cited by examiner]
US 20150326563A1 · Chan · 2015 [cited by examiner]
US 20200021993A1 · Yang et al. · 2020 [cited by examiner]
EP 2830016A1 · 2015 [cited by applicant]
WO 2020139513A1 · 2020 [cited by applicant]
PCT/EP2020/081375, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration”, International Searching Authority, May 17, 2021, … [cited by applicant]
Devanesan, “Samsung looks to 6G and beyond with blockchain and Al”, Techwire Asia, https://techwireasia.com/2020/09/samsung-looks-to-6g-and-beyond-with-blockchain-and-ai/, Sep. 10, 2020, pp. 1-10. [cited by applicant]
European Commission, “eIDAS Regulation”, https://ec.europa.eu/digital-single-market/en/trust-services-and-eid, https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation, Jun. 7, 2022, pp. 1-8. [cited by applicant]
GMSA, “Blockchain for Development: Emerging Opportunities for Mobile, Identity and Aid”, https://www.gsma.com/mobilefordevelopment/wp-content/uploads/2017/12/Blockchain-for-Development.pdf, 2017, pp. 1-17. [cited by applicant]
ITU News, “How mobile operators can help create an inclusive digital identity system”, https://news.itu.int/mobile-operators-digital-identity-system/, Jul. 23, 2018, pp. 1-11. [cited by applicant]
Ledger Insights, “SK Telecom, Deutsche Telekom plan blockchain digital identity”, https://www.ledgerinsights.com/sk-telecom-deutsche-telekom-blockchain-digital-identity/, Feb. 21, 2019, pp. 1-13. [cited by applicant]
Seregin, “SK Telecom und Deutsche Telekom mit Blockchain ID-System”, https://blockchainwelt.de/sk-telecom-und-deutsche-telekom-kooperieren-bei-blockchain-id-system/, Apr. 20, 2022, pp. 1-7. [cited by applicant]
W3C, “Decentralized Identifiers (DIDs) v1.0 Core architecture, data model, and representations”, https://www.w3.org/TR/did-core/, Jul. 19, 2022, pp. 1-147. [cited by applicant]
Thales, “Digital Customer Onboarding with Trusted Digital Identities (Whitepaper)”, https://www.thalesgroup.com/en/markets/digital-identity-and-security/mobile/documents/digital-onboarding-digital-identity, 2023, pp. 1-… [cited by applicant]
Thales, “Digital identity 2.0—Self-sovereign identities at work”, https://www.thalesgroup.com/en/markets/digital-identity-and-security/banking-payment/digital-identity, 2023, pp. 1-7. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16)”, 3GPP TS 33.501 V16.4.0, Sep. 2020, pp. 1-250. [cited by applicant]
W3C, “Eidas Supported Self-Sovereign Identity”, https://ec.europa.eu/futurium/en/system/files/ged/eidas_supported_ssi_may_2019_0.pdf, May 2019, pp. 1-13. [cited by applicant]
Windley, “Multi-Source and Self-Sovereign Identity”, https://www.windley.com/archives/2018/09/multi-source_and_self-sovereign_identity.shtml, Sep. 10, 2018, pp. 1-7. [cited by applicant]