IP Library Granted Patent US 12,647,267
Granted Patent B2
US 12,647,267 · App. 18/674,804 · Granted Jun 2, 2026

Attribute-based credentials for resource access

Inventors: Andreas Kunz (Ladenburg, DE); Sheeba Backia Mary Baskaran (Friedrichsdorf, DE)
Assignee: Lenovo (Singapore) Pte Ltd
H04L9/32H04L9/3006
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,267
App. No.
18/674,804
Granted
Jun 2, 2026
Kind
B2
Abstract

Various aspects of the present disclosure relate to attribute-based credentials for resource access. An apparatus, such as a UE, generates one or more credentials comprising one or more first public keys and one or more attributes associated with a service request. The apparatus communicates a credential issuance request comprising at least a portion of the one or more credentials, and receives, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys and one or more encrypted subscription identities associated with the service request.

Claims (53)

1 . A user equipment (UE) for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the UE to:

generate a first set of credentials comprising one or more first public keys and one or more attributes associated with a service request;

communicate a credential issuance request comprising at least a portion of the first set of credentials;

receive, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys and one or more encrypted subscription identities associated with the service request;

generate the one or more encrypted root keys and the one or more encrypted subscription identities; and

generate a second set of credentials to include the one or more encrypted root keys and the one or more encrypted subscription identities.

2 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to one or more of:

generate the one or more first public keys based at least in part on a number of the first set of credentials; or

generate the one or more first public keys based at least in part on a number of the one or more attributes to be bound to an instance of the one or more first public keys.

3 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to generate the one or more encrypted root keys and the one or more encrypted subscription identities using a second public key.

4 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to generate a third set of credentials to include at least one of one or more pseudonyms, a device identity associated with the UE, a network type associated with the service request, a network name associated with the service request, or revocation information associated with the first set of credentials.

5 . The UE of claim 4 , wherein the third set of credentials include proof information for a private key of the UE and a random number, the random number used to compute the proof information for the private key.

6 . The UE of claim 1 , wherein the one or more encrypted subscription identities comprise one or more encrypted subscription permanent identifiers (SUPIs).

7 . The UE of claim 1 , wherein the credential issuance request further comprises revocation information associated with the first set of credentials.

8 . The UE of claim 1 , wherein the first set of credentials do not include the one or more encrypted root keys or the one or more encrypted subscription identities.

9 . The UE of claim 1 , wherein the service request comprises a request for access to a wireless communication network.

10 . A processor for wireless communication, comprising:

at least one controller coupled with at least one memory and configured to cause the processor to:

generate a first set of credentials comprising one or more first public keys and one or more attributes associated with a service request for a user equipment (UE);

communicate a credential issuance request comprising at least a portion of the first set of credentials;

receive, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys, and one or more encrypted subscription identities associated with the service request;

generate the one or more encrypted root keys and the one or more encrypted subscription identities; and

generate a second set of credentials to include the one or more encrypted root keys and the one or more encrypted subscription identities.

11 . The processor of claim 10 , wherein the at least one controller is configured to cause the processor to generate a third set of credentials to include at least one of one or more pseudonyms, a device identity associated with the UE, a network type associated with the service request, a network name associated with the service request, or revocation information associated with the first set of credentials.

12 . The processor of claim 10 , wherein the credential issuance request further comprises revocation information associated with the first set of credentials.

13 . The processor of claim 10 , wherein the first set of credentials do not include the one or more encrypted root keys or the one or more encrypted subscription identities.

14 . A network equipment for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the network equipment to:

receive a key generation request associated with a service request by a user equipment (UE), the key generation request comprising one or more first public keys associated with the UE and one or more one or more second public keys;

generate a root key and a subscription identity associated with the service request;

encrypt the root key and the subscription identity using the one or more first public keys and one or more second public keys to generate an encrypted root key and an encrypted subscription identity;

communicate a key generation response comprising the encrypted root key and the encrypted subscription identity;

receive the encrypted root key and the encrypted subscription identity; and

receive one or more credentials to include the encrypted root key and the encrypted subscription identity.

15 . The network equipment of claim 14 , wherein the at least one processor is configured to cause the network equipment to one or more of:

separately encrypt the root key and the subscription identity using the one or more first public keys and one or more second public keys; or

encrypt the root key and the subscription identity together using the one or more first public keys and one or more second public keys.

16 . The network equipment of claim 14 , wherein the at least one processor is configured to cause the network equipment to sign the encrypted root key and the encrypted subscription identity with the one or more second public keys.

17 . The network equipment of claim 14 , wherein the key generation response further comprises revocation information for a credential associated with the service request.

18 . A method performed by a user equipment (UE), the method comprising:

generating a first set of credentials comprising one or more first public keys and one or more attributes associated with a service request;

communicating a credential issuance request comprising at least a portion of the first set of credentials;

receiving, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys, and one or more encrypted subscription identities associated with the service request;

generating the one or more encrypted root keys and the one or more encrypted subscription identities; and

generating a second set of credentials to include the one or more encrypted root keys and the one or more encrypted subscription identities.

19 . The method of claim 18 , further comprising:

generating the one or more first public keys based at least in part on a number of the first set of credentials; or

generating the one or more first public keys based at least in part on a number of the one or more attributes to be bound to an instance of the one or more first public keys.

20 . The method of claim 18 , further comprising:

generating the one or more encrypted root keys and the one or more encrypted subscription identities using a second public key.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2024
From: LENOVO (UNITED STATES) INC.
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 069278/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2024
From: KUNZ, ANDREAS; BASKARAN, SHEEBA BACKIA MARY
To: LENOVO (UNITED STATES) INC.
Reel/Frame 067649/0036 →
Continuity (1)
Related Publication 20250365150A1 · Nov 27, 2025
References Cited (52)
US 9240886B1 · Allen et al. · 2016 [cited by applicant]
US 11076288B2 · Torvinen · 2021 [cited by examiner]
US 12155781B1 · Helfgott · 2024 [cited by examiner]
US 20060206932A1 · Chong · 2006 [cited by examiner]
US 20060235796A1 · Johnson · 2006 [cited by examiner]
US 20170033934A1 · Camenisch et al. · 2017 [cited by applicant]
US 20170034142A1 · Camenisch et al. · 2017 [cited by applicant]
US 20190020480A1 · Camenisch et al. · 2019 [cited by applicant]
US 20190295069A1 · Pala · 2019 [cited by examiner]
US 20200014535A1 · Baskaran · 2020 [cited by examiner]
US 20210320788A1 · Kang · 2021 [cited by examiner]
US 20210385216A1 · Khalil · 2021 [cited by examiner]
US 20220122170A1 · Du · 2022 [cited by examiner]
US 20220191044A1 · Kurita · 2022 [cited by examiner]
US 20220225093A1 · Sasi · 2022 [cited by examiner]
US 20230031804A1 · Shimizu · 2023 [cited by examiner]
US 20230164143A1 · Richardson, IV · 2023 [cited by examiner]
US 20230224704A1 · Atarius et al. · 2023 [cited by applicant]
US 20230269095A1 · Yamaoka · 2023 [cited by examiner]
US 20230412379A1 · Yanai · 2023 [cited by applicant]
US 20230413060A1 · Baskaran · 2023 [cited by examiner]
US 20240022433A1 · Asor · 2024 [cited by examiner]
US 20240106834A1 · Yamaoka · 2024 [cited by examiner]
US 20240297798A1 · Shimizuike · 2024 [cited by examiner]
US 20250131134A1 · Giffard-Burley · 2025 [cited by examiner]
US 20250159476A1 · Torvinen · 2025 [cited by examiner]
US 20250217795A1 · Modadugu · 2025 [cited by examiner]
US 20250365576A1 · Kunz et al. · 2025 [cited by applicant]
CN 112600850B · 2022 [cited by examiner]
CN 116318981A · 2023 [cited by examiner]
WO WO2022096125A1 · 2022 [cited by examiner]
WO WO2022096126A1 · 2022 [cited by examiner]
WO WO2023212051A1 · 2023 [cited by examiner]
WO WO2024236072A1 · 2024 [cited by examiner]
WO WO2024162661A1 · 2024 [cited by examiner]
WO WO2025099848A1 · 2025 [cited by examiner]
Chen, Yuan et al. CN 116318981 A (machine translation), published Jun. 23, 2023. (Year: 2023). [cited by examiner]
Yamauchi, Kenta et al. WO 2025099846 A1 (machine translation), published May 15, 2025. (Year: 2025). [cited by examiner]
Lai, Jun-zuo et al. CN 112600850 B (machine translation), published May 3, 2022. (Year: 2022). [cited by examiner]
E. Zeydan, J. Mangues, S. S. Arslan and Y. Turk, “Decentralizing Authentication for Mobile Networks: Opportunities and Challenges in Web 3.0 Era,” in IEEE Wireless Communications, vol. 32, No. 1, pp. 206-212, Feb. 2025.… [cited by examiner]
Yu, Hexuan, et al. “Aaka: An anti-tracking cellular authentication scheme leveraging anonymous credentials.” Network and Distributed System Security (NDSS) Symposium 2024. Internet Society, Feb. 2024. (Year: 2024). [cited by examiner]
W3C. “Verifiable Credentials Data Model v2.0”, Mar. 2023. Retrieved from <https://www.w3.org/TR/2023/WD-vc-data-model-2.0-20230803/#dfn-verifiable-credential>. (Year: 2023). [cited by examiner]
Kakvi, Saqib A., et al. “Sok: anonymous credentials.” International Conference on Research in Security Standardisation. Cham: Springer Nature Switzerland, 2023. (Year: 2023). [cited by examiner]
Hampiholi, Brinda, and Bart Jacobs. “Trusted self-enrolment for attribute-based credentials on mobile phones.” Proceedings of the IFIP Summer School (2015). (Year: 2015). [cited by examiner]
3GPP. “5G; Security architecture and procedures for 5G System” (3GPP TS 33.501 version 15.18.0 Release 15), Apr. 2024. (Year: 2024). [cited by examiner]
3GPP , “Security architecture and procedures for 5G system (Release 16)”, 3GPP TS 33.501 V16.18.0, retrieved from the internet on May 20, 2024, <https://www.3gpp.org/ftp/Specs/archive/33_series/33.501/>, Mar. 2024, 257 … [cited by applicant]
ABC4Trust , “Attribute-based Credentials for Trust”, retrieved from the internet on May 20, 2024, <https://abc4trust.eu/download/flyer/ABC4Trust-OnePager-About-ABC4Trust.pdf>, Sep. 2011, 2 pages. [cited by applicant]
Bischsel , et al., “D2.2—Architecture for Attribute-based Credential Technologies—Final Version”, retrieved from the internet on May 21, 2024, <https://abc4trust.eu/download/Deliverable_D2.2.pdf>, 2014, 149 pages. [cited by applicant]
Korenhof , et al., “The ABC of ABC: An analysis of attribute-based credentials in the light of data protection, privacy and identity”, In J. B. Padulles, A. C. i Martínez, M. P. Poch, I. P. López, M. J. P. de Moner, & M… [cited by applicant]
Bernabe et al., “Holistic Privacy-Preserving Identity Management System for the Internet of Things,” Hindawi, Mobile Information Systems, Wiley, vol. 2017, Article ID 6384186, Aug. 8, 2017, 21 pages. [cited by applicant]
Non-Final Office Action issued in U.S. Appl. No. 18/674,808, mailed Dec. 18, 2025, 20 pages. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 18/674,808, mailed Apr. 15, 2026, 9 pages. [cited by applicant]
Cited By (1)
US 12,739,633