IP Library Granted Patent US 12684345
Granted Patent B2
US 12684345 · App. 18/312,391 · Granted Jul 14, 2026

Key management for cloud-based 5G wireless networks

Inventors: Steven Wilson (Englewood, CO); Brian Peletz (Aurora, CO)
Assignee: Boost SubscriberCo L.L.C.
H04W12/04G06F9/45558H04L9/0825
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12684345
App. No.
18/312,391
Filed
May 4, 2023
Granted
Jul 14, 2026
Kind
B2
Art Unit
2455
USPC
380/270
Abstract

Systems, devices and automated processes are described to securely grant access to components of a cloud-based data processing system implementing a 5G wireless network. Secure mechanisms are provided to generate, store and retrieve private and public encryption keys that are associated with virtual machines implementing the various components of the wireless network. Generated keys can be retrieved from secure storage associated with the data processing system to provide access to the components as desired.

Claims (37)

1 . An automated process to secure access by a client to a virtual machine (VM) component of a cloud-based data processing system that implements a 5G wireless network, the automated process comprising:

associating the component of the cloud-based data processing system with a cryptographic key pair comprising a public key and a private key;

storing the private key associated with the VM component in a secure digital storage and separately storing the public key associated with the VM component with a VM management service associated with the cloud based data processing system;

subsequently receiving, by the VM management service, a request for access to the VM component of the cloud-based data processing system by the client;

verifying the request for access to the VM component received from the client by the VM management service;

when the request for access is verified, providing the public key associated with the VM component of the cloud-based data processing system from the VM management service to the client in response to the request and otherwise denying access to the VM components;

subsequently receiving, by the secure digital storage, a session request from the client that comprises the public key associated with the VM component of the cloud-based data processing system that the client previously obtained from the VM management service; and

responsively providing the private key associated with the VM component of the cloud-based data processing system from the secure digital storage to a secure plugin component associated with the client, wherein the secure plugin component associated with the client receives the private key and uses the private key obtained from the secure digital storage to provide access by the client to the VM component of the cloud-based data processing system without granting a user associated with the client access to view, store, forward and duplicate the private key that is associated with the VM component to there by maintain security of the VM components of the cloud-based data processing system.

2 . The automated process of claim 1 further comprising authenticating the client with the VM management service, wherein the authenticating comprises providing the client with a digital credential upon successful authentication.

3 . The automated process of claim 2 wherein the request for access to the VM component of the cloud-based data processing system by the client comprises the digital credential.

4 . The automated process of claim 3 wherein the public key associated with the VM component of the cloud-based data processing system to the client is provided to the client in response to successful authentication of the digital credential received from the client.

5 . The automated process of claim 1 wherein the secure plugin component augments a secure shell (SSH) protocol executed by the client.

6 . The automated process of claim 5 wherein the VM component of the cloud-based data processing system is a virtual machine implementing a service of the 5G wireless network.

7 . The automated process of claim 6 wherein the VM management service is a virtual machine management service executing on hardware associated with the data processing system.

8 . The automated process of claim 7 wherein the VM management service is a VSPHERE service executed within the data processing system.

9 . The automated process of claim 8 wherein the VM component of the cloud-based data processing system is a virtual machine implementing a centralized unit (CU) of the 5G wireless network.

10 . The automated process of claim 6 wherein the secure digital storage comprises a database having restricted access.

11 . A cloud-based data processing system that implements a 5G wireless network, the data processing system comprising a processor and memory configured to perform an automated process comprising:

associating a virtual machine (VM) component of the cloud-based data processing system with a cryptographic key pair comprising a public key and a private key;

storing the private key associated with the VM component in a secure digital storage and separately storing the public key associated with the VM component with a VM management service associated with the cloud based data processing system;

subsequently receiving, by the VM management service, a request for access to the VM component of the cloud-based data processing system from a client that is associated with a user;

verifying the request for access to the VM component by the VM management service;

when the request for access to the VM component is verified, then providing the public key associated with the VM component of the cloud-based data processing system to the client in response to the request, and otherwise denying access to the VM component;

subsequently receiving, by the secure digital storage, a session request from the client that comprises the public key associated with the VM component of the cloud-based data processing system that was previously provided to the client by the VM management service; and

responsively providing the private key associated with the VM component of the cloud-based data processing system to a secure plugin component associated with the client, wherein the secure plugin component associated with the client receives the private key that is associated with the VM component and uses the private key to access the VM component of the cloud-based data processing system without granting the user associated with the client access to view, store, forward and duplicate the private key to thereby maintain security of the VM components of the cloud-based data processing system.

12 . The cloud-based data processing system of claim 11 further comprising authenticating the client with the VM management service, wherein the authenticating comprises providing the client with a digital credential upon successful authentication.

13 . The cloud-based data processing system of claim 12 wherein the request for access to the VM component of the cloud-based data processing system by the client comprises the digital credential, and wherein the public key associated with the VM component of the cloud-based data processing system is provided to the client in response to successful authentication of the digital credential received from the client.

14 . The cloud-based data processing system of claim 11 wherein secure plugin component augments a secure shell (SSH) protocol executed by the client.

15 . The cloud-based data processing system of claim 14 wherein the VM component of the cloud-based data processing system is a virtual machine implementing a service of the 5G wireless network.

16 . The cloud-based data processing system of claim 11 wherein the secure digital storage is a portion of the memory having restricted access.

17 . A data processing system to provide access by a client to a virtual machine (VM) component of a cloud processing system that implements a wireless network, the data processing system comprising:

a secure data storage configured to store a private key from an asymmetric key pair associated with the component of the cloud processing system; and

a VM management system that comprises a processor configured to store a public key from the asymmetric key pair associated with the VM component of the cloud processing system, to perform an authentication of the client, and, upon successful authentication of the client, to provide the public key from the asymmetric key pair associated with the VM component of the cloud processing system to the client and to otherwise deny access to the VM component of the cloud processing system;

wherein a plugin is configured to augment a secure shell (SSH) protocol executed by the client, wherein if the authentication is successful, the plugin provides the public key associated with the VM component to the secure data storage to thereby retrieve the private key associated with the VM component from the secure storage to thereby provide access by the client to the VM component of the cloud processing system without granting access to view, store, forward and duplicate the private key to thereby maintain security of the VM components of the cloud-based data processing system.

18 . The data processing system of claim 17 wherein the VM component is a virtual machine (VM) executed by the cloud-based data processing system.

19 . The data processing system of claim 18 wherein the VM component implements a central unit CU of the wireless network.

20 . The data processing system of claim 17 wherein the plugin is configured to provide the private key to the VM component without allowing direct access to the private key by a user of the client.