IP Library Granted Patent US 12695591
Granted Patent B2
US 12695591 · App. 18/603,996 · Granted Jul 28, 2026

Security in networks

Inventors: Jean-Luc Rene Bouthemy (Sammamish, WA); Gregg Allan Atkins (Bellevue, WA)
Assignee: T-Mobile USA, Inc.
H04L9/006H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695591
App. No.
18/603,996
Filed
Mar 13, 2024
Granted
Jul 28, 2026
Kind
B2
Art Unit
2493
USPC
713/151
Abstract

Techniques related to providing secure communications in a network are disclosed. In one example, an alternative for providing secure communication in an automated way in a network including retrieving by a network server configured to manage one or more network nodes in the network a security certificate and other security configuration corresponding to a network node. Transmitted, by the network server, including pair(s) of public and private keys and other parameters to the network node to enable the network node to establish a secure communication channel with at least another network node.

Claims (53)

1 . A hardware system for secure communication in a network, comprising:

a first network server configured to manage one or more security certificates for the network; and

a second network server configured to manage an operation of one or more network nodes in the network,

wherein the second network server is configured to:

retrieve the one or more security certificates and one or more security configurations from the first network server; and

transmit, based on (1) the one or more security certificates and (2) a first security configuration of the one or more security configurations retrieved from the first network server, a first pair of public and private keys to a first network node to enable the first network node to establish a first communication channel with a second network node using a first encrypted communication protocol according to the first security configuration,

wherein the first communication channel is within a first network slice; and

transmit, based on (1) the one or more security certificates and (2) a second security configuration of the one or more security configurations retrieved from the first network server, a second pair of public and private keys to a third network node to enable the third network node to establish a second communication channel with at least a fourth network node,

wherein the second communication channel is within a second network slice different from the first network slice and uses a second encrypted communication protocol different from the first encrypted communication protocol, and

wherein the second encrypted communication protocol is according to the second security configuration different from the first security configuration.

2 . The hardware system of claim 1 , wherein the first network server comprises a Public Key Infrastructure or a certificate management server.

3 . The hardware system of claim 1 , wherein the second network server is configured to:

determine configuration information for the first network node based on the one or more security certificates; and

transmit the configuration information to the first network node.

4 . The hardware system of claim 3 , wherein the configuration information comprises the first pair of public and private keys, and wherein the second network server is configured to transmit the first pair of public and private keys to the first network node by transmitting the configuration information to the first network node.

5 . The hardware system of claim 3 , wherein the second network server is further configured to:

receive, in response to the configuration information, credential information from the first network node; and

determine the first pair of public and private keys based on the credential information of the first network node.

6 . The hardware system of claim 1 , wherein the second network server is configured to:

receive information about the one or more network nodes from a third network server, the information comprising at least one of an image of a network node, a configuration parameter of the network node, or an attribute of the network node.

7 . The hardware system of claim 6 , wherein the information about the one or more network nodes comprises credential information of the one or more network nodes, the credential information comprising at least a digital signature of a network node.

8 . The hardware system of claim 6 , wherein the information about the one or more network nodes comprises an initial set of public and private keys to enable a network node to establish a secure communication channel with the second network server.

9 . The hardware system of claim 1 , wherein the second network server is configured to:

determine configuration information for the first network node based on the one or more security certificates; and

transmit the configuration information to an operational support server to enable the operational support server to forward the configuration information to the one or more network nodes.

10 . The hardware system of claim 1 , wherein the second network server comprises a network orchestrator.

11 . The hardware system of claim 1 , wherein the first network node and the second network node are network functions configured in a network slice.

12 . The hardware system of claim 1 , wherein the first network node comprises a radio access node.

13 . The hardware system of claim 1 , wherein the first communication channel is established at a transport layer of the first network node and the second network node.

14 . A method for providing secure communication in a network, comprising:

retrieving, by a network server configured to manage one or more network nodes in the network, a security certificate and one or more security configurations corresponding to a first network node of the one or more network nodes; and

transmitting, by the network server (1) based on the security certificate and (2) a first security configuration of the one or more security configurations, a first pair of public and private keys to the first network node to enable the first network node to establish a first secure communication channel with at least a second network node of the one or more network nodes using a first encrypted communication protocol according to the first security configuration,

wherein the first secure communication channel is within a first network slice; and

transmitting, based on (1) the security certificate and (2) a second security configuration of the one or more security configurations, a second pair of public and private keys to a third network node of the one or more network nodes to enable the third network node to establish a second secure communication channel with at least a fourth network node of the one or more network nodes,

wherein the second secure communication channel is within a second network slice different from the first network slice and uses a second encrypted communication protocol different from the first encrypted communication protocol, and

wherein the second encrypted communication protocol is according to the second security configuration different from the first security configuration.

15 . The method of claim 14 , wherein the one or more network nodes comprise at least a network function or a base station in a radio access network.

16 . The method of claim 14 , wherein the first encrypted communication protocol comprises at least one of a Post-Quantum security protocol, a Transport Layer Security (TLS) protocol, an mTLS protocol, a Datagram TLS (DTLS) protocol, or an Internet-Protocol Security (IPsec) protocol.

17 . The method of claim 14 , comprising:

determining, by the network server, configuration information for the first network node based on the security certificate; and

transmitting, by the network server, the configuration information to the first network node.

18 . The method of claim 17 , wherein the configuration information comprises the first pair of public and private keys, and wherein the configuration information comprises an Internet Protocol (IP) configuration of at least a communication interface of the first network node.

19 . A method for providing secure communication in a network, comprising:

determining, by a first network node in the network and determined based on one or more security certificates and one or more security configurations, a first pair of public and private keys and a second pair of public and private keys;

establishing, by the first network node and based on (1) the one or more security certificates and (2) a first security configuration of one or more security configurations, a first secure communication channel with a second network node based on a first encryption protocol using the first pair of public and private keys,

wherein the first encryption protocol is according to the first security configuration, and

wherein the first secure communication channel is within a first network slice of the network; and

establishing, by the first network node and based on (1) the one or more security certificates and (2) a second security configuration of the one or more security configurations, a second secure communication channel, within a second network slice of the network that is different from the first network slice, with a third network node based on a second encryption protocol using the second pair of public and private keys,

wherein the second encryption protocol is according to the second security configuration different from the first security configuration, and

wherein the second encryption protocol is different from the first encryption protocol.

20 . The method of claim 19 , further comprising:

receiving, by the first network node, an initial pair of public and private keys; and

establishing an initial communication channel with a network server using the initial pair of public and private keys.