Patents by Inventor Andreas Kunz

Andreas Kunz has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12719874
    Abstract: Various aspects of the present disclosure relate to a network repository function (NRF) that receives a first signaling as a network function (NF) request from a NF, the NF request including a NF type, a NF identifier (ID), and NF security state information. The NRF verifies a NF security state based on the NF ID and the NF security state information. The NRF transmits a second signaling as a NF response, where the NF response includes a security verification of the NF request.
    Type: Grant
    Filed: June 13, 2023
    Date of Patent: August 25, 2026
    Assignee: Lenovo (Singapore) Pte. Limited
    Inventors: Sheeba Backia Mary Baskaran, Andreas Kunz
  • Publication number: 20260247133
    Abstract: Various aspects of the present disclosure relate to temporary identifiers for devices in a group. A device receives a group inventory request that includes a group identifier (ID) and a correlation ID. The device generates a temporary ID for the device based at least in part on the correlation ID and an individual ID of the device, and transmits an inventory response that includes the temporary ID for the device and the correlation ID. The device can receive a command request that includes a second temporary ID, perform, based at least in part on the second temporary ID matching the temporary ID of the device, a command indicated by the command request, and transmit a command response message that includes the second temporary ID.
    Type: Application
    Filed: February 14, 2025
    Publication date: August 20, 2026
    Applicant: Lenovo (United States) Inc.
    Inventors: Andreas Kunz, Hyung-Nam Choi, Genadi Velev, Karthikeyan Ganesan, Sheeba Backia Mary Baskaran
  • Publication number: 20260239007
    Abstract: Various aspects of the present disclosure relate to application programming interface (API) invoker authentication. An API invoker/UE transmits an onboard API invoker request including a UE identifier, a first authentication code, and a first freshness parameter. The API invoker/UE receives an onboard API invoker response including an API invoker certificate associated with the UE identifier and one or more application identifiers (A-IDs), and an API invoker secret associated with the UE identifier and one or more A-IDs.
    Type: Application
    Filed: February 7, 2025
    Publication date: August 13, 2026
    Applicant: Lenovo (United States) Inc.
    Inventors: Sheeba Backia Mary Baskaran, Andreas Kunz
  • Publication number: 20260230819
    Abstract: Various aspects of the present disclosure relate to UE TNAP Mobility. For example, the technology can provide UE TNAP Mobility authentication and security establishment procedures, such as procedures that utilize new input parameters and security key refreshes during the authentication and security establishment procedures when a UE moves from a source TNAP to a target TNAP.
    Type: Application
    Filed: February 1, 2024
    Publication date: August 6, 2026
    Inventors: Sheeba Backia Mary BASKARAN, Andreas KUNZ
  • Patent number: 12696087
    Abstract: Various aspects of the present disclosure relate to transmitting a first request message comprising a first set of parameters. Aspects of the present disclosure may relate to receiving a first response message comprising an indication that a device is unreachable. Aspects of the present disclosure may relate to resetting a sequence number (SQN) and a device profile for the device in response to the first response message. Aspects of the present disclosure may relate to transmitting a second request message comprising a second set of parameters, wherein the second set of parameters comprises a default identifier (ID) of the device, a nonce, and the SQN. Aspects of the present disclosure may relate to receiving a second response message from the device comprising a result based on the default ID.
    Type: Grant
    Filed: November 1, 2024
    Date of Patent: July 28, 2026
    Assignee: Lenovo (United States) Inc.
    Inventors: Andreas Kunz, Sheeba Backia Mary Baskaran
  • Patent number: 12689899
    Abstract: Various aspects of the present disclosure relate to secure data collection via a messaging framework. An apparatus includes at least one memory and at least one processor that is configured to receive a subscription request from a data consumer function, the subscription request comprising a data tag associated with a data producer function, generate a security key for the data tag, generate a binding for the data tag between the security key, the data consumer function, and the data producer function, and transmit, for use in data transmissions between the data producer function and the data consumer function a service request message to the data producer function, the service request message comprising the data tag and the security key, and a data exposure response message to the data consumer function, the data exposure response message comprising the data tag and the security key.
    Type: Grant
    Filed: February 21, 2022
    Date of Patent: July 21, 2026
    Assignee: Lenovo (Singapore) Pte. Ltd.
    Inventors: Andreas Kunz, Dimitrios Karampatsis, Sheeba Backia Mary Baskaran
  • Publication number: 20260205225
    Abstract: Apparatuses, methods, and systems are disclosed for wireless communication, including wireless communications for providing a blind assistance service. One method includes receiving, from a blind assistance device, a service request indication associated with a blind assistance service. The method includes determining an availability of a subscription to the blind Begin assistance service. The method includes transmitting a pairing authorization request to a NF for the blind assistance service.
    Type: Application
    Filed: March 27, 2024
    Publication date: July 16, 2026
    Inventors: Sheeba Backia Mary Baskaran, Prateek Basu Mallick, Andreas Kunz
  • Publication number: 20260197648
    Abstract: Various aspects of the present disclosure relate to authorizing services related to artificial intelligence machine learning enablement (AIMLE) client device management. A service device may transmit a first message requesting an access token including a scope related to an AIMLE client device management service. The service device may receive, responsive to the first message, a second message including the access token, the access token including one or more claims associated with the scope that identify one or more permissions for the AIMLE client device management service.
    Type: Application
    Filed: October 8, 2025
    Publication date: July 9, 2026
    Applicant: Lenovo (United States) Inc.
    Inventors: Sheeba Backia Mary Baskaran, Andreas Kunz
  • Patent number: 12672000
    Abstract: Apparatuses, methods, and systems are disclosed for UAS authentication and security establishment. One apparatus includes a transceiver that sends, from a first network function of a mobile wireless communication network, an authentication request message from a user equipment (“UE”) to a UAS Service Supplier (“USS”)/UAS Traffic Management (“UTM”), the UE comprising at least one of an unmanned aerial vehicle (“UAV”) and a UAV controller (“UAV-C”). The transceiver receives, at the first network function from the USS/UTM, an authentication response message comprising a UAS identifier and a UAS security context.
    Type: Grant
    Filed: August 6, 2021
    Date of Patent: June 30, 2026
    Assignee: Lenovo (Singapore) Pte. Ltd.
    Inventors: Sheeba Backia Mary Baskaran, Andreas Kunz, Dimitrios Karampatsis
  • Publication number: 20260180848
    Abstract: Apparatuses, methods, and systems are disclosed for determining a network system issue. One method includes a first network device determining a system issue corresponding to at least one second network device. The first network device is an analytics entity in a cellular network and the at least one second network device is a managed entity in the cellular network, and the system issue comprises a software issue, a hardware issue, a compatibility issue, an issue with an interaction between a plurality of second network devices comprising the at least one second network device, an issue with an interaction between the at least one second network device and another device, or some combination thereof. The analytics entity comprises an entity that analyzes one or more devices to determine descriptive analytics, predictive analytics, and/or prescriptive analytics. The method includes providing a notification indicating the system issue.
    Type: Application
    Filed: February 18, 2026
    Publication date: June 25, 2026
    Inventors: Ishan Vaishnavi, Andreas Kunz, Sheeba Backia Mary Baskaran, Apostolis Salkintzis, Dimitrios Karampatsis
  • Publication number: 20260181383
    Abstract: There is provided a method comprising: receiving an NI message from a user equipment “UE” over a Non-Terrestrial Network “NTN” service; sending a get request to a UDM which includes UE ID, NTN service type and an indication for a privacy information check; receiving a get response from the UDM with UE ID, NTN service type, and privacy information; and responding to the NI message based on the received privacy information.
    Type: Application
    Filed: December 9, 2022
    Publication date: June 25, 2026
    Inventors: Sheeba Backia Mary BASKARAN, Robin Rajan THOMAS, Hyung-Nam CHOI, Sher Ali CHEEMA, Andreas KUNZ, Konstantinos SAMDANIS
  • Patent number: 12659735
    Abstract: Apparatuses, methods, and systems are disclosed for supporting remote unit reauthentication. One apparatus apparatus includes a processor and a transceiver that sends a first authentication message to a network function in a mobile communication network and receives a second authentication message from the network function in response to the first authentication message. Here, the first authentication message contains an indicator that the apparatus supports EAP Reauthentication Protocol and the second authentication message contains a key management domain name indicating a group of network functions that can share reauthentication security context. The processor derives reauthentication security context in response to successful authentication with the mobile communication network and locally stores the received key management domain name and the derived reauthentication security context for subsequent reauthentication with the mobile communication network.
    Type: Grant
    Filed: June 5, 2020
    Date of Patent: June 16, 2026
    Assignee: Lenovo (Singapore) Pte. Ltd.
    Inventors: Andreas Kunz, Apostolis Salkintzis, Sheeba Backia Mary Baskaran
  • Patent number: 12659740
    Abstract: Apparatuses, methods, and systems are disclosed for registration authentication based on a capability. One method includes receiving, at a second network device from a first network device, an indication for a capability for a registration. The method includes transmitting, to a third network device, a first request for a type of authentication procedure for the registration. The method includes transmitting, to a remote unit, a second request. The second request corresponds to the type of authentication procedure for the registration. The method includes receiving, from the remote unit, a response to the second request. The response corresponds to a stored credential in the remote unit.
    Type: Grant
    Filed: March 14, 2022
    Date of Patent: June 16, 2026
    Assignee: Lenovo (Singapore) Pte. Ltd.
    Inventors: Roozbeh Atarius, Andreas Kunz, Genadi Velev
  • Patent number: 12647267
    Abstract: Various aspects of the present disclosure relate to attribute-based credentials for resource access. An apparatus, such as a UE, generates one or more credentials comprising one or more first public keys and one or more attributes associated with a service request. The apparatus communicates a credential issuance request comprising at least a portion of the one or more credentials, and receives, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys and one or more encrypted subscription identities associated with the service request.
    Type: Grant
    Filed: May 24, 2024
    Date of Patent: June 2, 2026
    Assignee: Lenovo (Singapore) Pte Ltd
    Inventors: Andreas Kunz, Sheeba Backia Mary Baskaran
  • Patent number: 12647787
    Abstract: Apparatuses, methods, and systems are disclosed for network function reallocation with security context. One apparatus includes a processor and a transceiver. The processor is configured to detect, at a first network function of a mobile wireless communication network, that the first network function cannot serve a requested network slice from a user equipment (“UE”) device. The transceiver is configured to send, from the first network function via a second network function, a reroute message to a third network function of the mobile wireless communication network. The reroute message includes an initial non-access stratum (“NAS”) message retrieved during NAS security mode command (“SMC”) procedure with the UE device and a security configuration. The third network function uses the initial NAS message and the security configuration to determine a security context for the UE device and serve the requested network slice from the UE device.
    Type: Grant
    Filed: June 28, 2021
    Date of Patent: June 2, 2026
    Assignee: Lenovo (Singapore) Pte. Ltd.
    Inventors: Andreas Kunz, Sheeba Backia Mary Baskaran, Genadi Velev
  • Publication number: 20260149579
    Abstract: Various aspects of the present disclosure relate to a mechanism that stores, for every subscription (e.g., each subscription permanent identifier, or SUPI, for subscribers of a network) individual key identifiers for the subscription in a reverse hash chain. For example, the mechanism, employed by a UE, may utilize a key identifier nonce and a key identifier hash chain length, generate a hash chain using the key identifier nonce as an initial value, where the hash chain has the key identifier hash chain length, select a last key identifier from the hash chain as a key identifier for a root key, and generate a concealed identifier for the UE using the root key (or a key derived from the root key).
    Type: Application
    Filed: January 12, 2026
    Publication date: May 28, 2026
    Inventors: Andreas KUNZ, Sheeba Backia Mary BASKARAN
  • Publication number: 20260149970
    Abstract: Apparatuses, methods, and systems are disclosed for supporting trusted non-3GPP gateway function (TNGF) reauthentication. A user equipment (UE) may include a processor coupled with at least one memory and configured to cause the UE to transmit a first extensible authentication protocol (EAP) message comprising a network access identifier (NAI) and receive a first EAP challenge packet in response to the NAI comprising the reauthentication identifier, wherein the NAI comprises a reauthentication identifier that indicates that the UE requests to reauthenticate with a gateway function, and wherein the first EAP challenge packet is used to authenticate the gateway function.
    Type: Application
    Filed: November 24, 2025
    Publication date: May 28, 2026
    Inventors: Apostolis Salkintzis, Sheeba Backia Mary Baskara, Andreas Kunz
  • Patent number: 12641428
    Abstract: Apparatuses, methods, and systems are disclosed for setting up multiple user plane (“UP”) security contexts. One apparatus includes a transceiver and a processor that derives distinct UP integrity and ciphering keys for a selected central unit user plane (“CU-UP”) node in the RAN, said derivation using a key derivation function. The processor assigns a UP Security Indicator to uniquely identify the derived distinct UP integrity and ciphering keys and the transceiver sends a setup request to the selected CU-UP node, said setup request containing the UP Security Indicator and the distinct UP integrity and ciphering keys. The transceiver receives a setup response from the selected CU-UP node and the processor activates distinct UP security at a UE.
    Type: Grant
    Filed: April 24, 2021
    Date of Patent: May 26, 2026
    Assignee: Lenovo (Singapore) Pte. Ltd.
    Inventors: Sheeba Backia Mary Baskaran, Andreas Kunz, Genadi Velev, Prateek Basu Mallick, Joachim Loehr, Hyung-Nam Choi
  • Publication number: 20260143342
    Abstract: Apparatuses, methods, and systems are disclosed for accessing a denied network resource. One apparatus includes a processor coupled with at least one memory and configured to cause the apparatus to transmit a registration request comprising a set of one or more network slices; receive a registration response comprising an empty allowed network slice selection assistance information (NSSAI) parameter; determine based on the empty allowed NSSAI parameter, to avoid other network services except emergency services; transmit an authentication response associated with a network slice specific authentication and authorization (NSSAA) procedure; and receive a reply message indicating that access to a network slice by a user equipment (UE) is denied due to a failed NSSAA of the UE or a revoked authorization of the UE.
    Type: Application
    Filed: January 14, 2026
    Publication date: May 21, 2026
    Inventors: Genadi Velev, Andreas Kunz
  • Publication number: 20260143340
    Abstract: Apparatuses, methods, and systems are disclosed for supporting gateway function reauthentication. One method includes generating a user equipment (UE) context for a UE in response to successful authentication of the UE; receiving a first request for the UE context from a first network function, the first request indicating that a second gateway function is to serve the UE, wherein the first request comprises a first set of parameters; deriving a first security key using at least one of the first set of parameters and a second security key stored in the UE context; and transmitting a modified UE context to the first network function, the modified UE context comprising the first security key.
    Type: Application
    Filed: January 9, 2026
    Publication date: May 21, 2026
    Inventors: Apostolis Salkintzis, Sheeba Backia Mary Baskaran, Andreas Kunz