IP Library › Granted Patent US 12,425,388
Granted Patent B2
US 12,425,388 · App. 17/159,346 · Granted Sep 23, 2025

Enhanced hop by hop security

Inventors: Nagendra Bykampadi (Bangalore, IN); Bruno Landais (Pleumeur-Bodou, FR); Silke Holtmanns (Klaukkala, FI); Jani Petteri Ekman (Kangasala, FI)
Assignee: NOKIA TECHNOLOGIES OY
H04L63/0823H04L9/30H04L67/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,388
App. No.
17/159,346
Granted
Sep 23, 2025
Kind
B2
Abstract

Embodiments of the present disclosure relate to methods, apparatuses and computer readable storage media for hop-by-hop security. A proposed method comprises receiving, at a first apparatus and from a second apparatus associated with a first network function, a message directed from the first network function to a second network function, the message comprising a first signature and network function information, the network function information at least comprising identification information of the first network function; in accordance with a successful validation of the first signature, updating the message with a second signature specific to a service communication proxy implemented by the first apparatus; and transmitting the updated message to a third apparatus associated with the second network function, the updated message comprising at least the second signature and the network function information.

Claims (103)

1. A first apparatus, configured to implement a service communication proxy connected to a first network function, the first apparatus comprising:

at least one processor; and

at least one memory including computer program codes;

the at least one memory and the computer program codes are configured to, with the at least one processor, cause the first apparatus to:

receive, from a second apparatus associated with the first network function, a message directed from the first network function to a second network function, the message comprising a first signature and network function information, the network function information at least comprising identification information of the first network function;

in accordance with a successful validation of the first signature, update the message with a second signature specific to the service communication proxy implemented by the first apparatus; and

transmit the updated message to a third apparatus associated with the second network function, the updated message comprising at least the second signature and the network function information,

wherein the network function information further comprises certificate information of the first network function, the second apparatus is configured to implement the first network function, and the first apparatus is caused to:

generate the second signature at least based on the first signature and a private key of the service communication proxy; and

insert the second signature into the message.

2. The apparatus of claim 1 , wherein the certificate information of the first network function comprises at least one of:

a client certificate of the first network function, or

an address which enables obtaining of a client certificate or a public key of the first network device.

3. The apparatus of claim 1 , wherein the identification information of the first network function comprises at least one of:

an instance identifier of the first network function,

a set identifier of the first network function, or

Fully Qualified Domain Name of the first network function.

4. The apparatus of claim 1 , wherein the first network function is a network function service consumer and the second network function is a network function service producer.

5. A first apparatus,

configured to implement a service communication proxy connected to a first network function, the first apparatus comprising:

at least one processor; and

at least one memory including computer program codes;

the at least one memory and the computer program codes are configured to, with the at least one processor, cause the first apparatus to:

receive, from a second apparatus associated with the first network function, a message directed from the first network function to a second network function, the message comprising a first signature and network function information, the network function information at least comprising identification information of the first network function;

in accordance with a successful validation of the first signature, update the message with a second signature specific to the service communication proxy implemented by the first apparatus; and

transmit the updated message to a third apparatus associated with the second network function, the updated message comprising at least the second signature and the network function information,

wherein the second apparatus is configured to implement the first network function, and the first apparatus is further caused to:

insert certificate information of the first network function into the message as part of the network function information;

generate the second signature at least based on the first signature and a private key of the service communication proxy; and

insert the second signature into the message.

6. The apparatus of claim 5 , wherein the network function information further comprises at least one of:

type information of the first network function, or

temporal information concerning transmission of the message.

7. The apparatus of claim 5 , wherein the identification information of the first network function comprises at least one of:

an instance identifier of the first network function,

a set identifier of the first network function, or

Fully Qualified Domain Name of the first network function.

8. The apparatus of claim 5 , wherein the first network function is a network function service consumer and the second network function is a network function service producer.

9. A first apparatus, configured to implement a service communication proxy connected to a first network function, the first apparatus comprising:

at least one processor; and

at least one memory including computer program codes;

the at least one memory and the computer program codes are configured to, with the at least one processor, cause the first apparatus to:

receive, from a second apparatus associated with the first network function, a message directed from the first network function to a second network function, the message comprising a first signature and network function information, the network function information at least comprising identification information of the first network function;

in accordance with a successful validation of the first signature, update the message with a second signature specific to the service communication proxy implemented by the first apparatus; and

transmit the updated message to a third apparatus associated with the second network function, the updated message comprising at least the second signature and the network function information,

wherein the network function information further comprises certificate information of the first network function, the second apparatus is configured to implement a further service communication proxy connected to the first network function, and the first apparatus is caused to:

generate the second signature at least based on the first signature and a private key of the service communication proxy; and

replace the first signature in the message with the second signature.

10. The apparatus of claim 9 , wherein the message further comprises a third signature specific to the first network function, and wherein the third apparatus is configured to implement the second network function.

11. The apparatus of claim 9 , wherein the identification information of the first network function comprises at least one of:

an instance identifier of the first network function,

a set identifier of the first network function, or

Fully Qualified Domain Name of the first network function.

12. The apparatus of claim 9 , wherein the first network function is a network function service consumer and the second network function is a network function service producer.

13. A second apparatus configured to implement a first network function, the second apparatus comprising:

at least one processor; and

at least one memory including computer program codes;

the at least one memory and the computer program codes are configured to, with the at least one processor, cause the second apparatus to:

generate a signature based on network function information, the network function information at least comprising identification information of the first network function, the signature specific to the first network function implemented by the second apparatus;

generate a message directed from the first network function to a second network function, the message comprising the signature and the network function information; and

transmit the message to a first apparatus, the first apparatus configured to implement a service communication proxy connected to the first network function, wherein the network function information further comprises at least one of:

certificate information of the first network function,

type information of the first network function, or

temporal information concerning transmission of the message, and

wherein the certificate information of the first network function comprises at least one of:

a client certificate of the first network function, or

an address which enables obtaining of a client certificate or a public key of the first network device.

14. The apparatus of claim 13 , wherein the identification information of the first network function comprises at least one of:

an instance identifier of the first network function,

a set identifier of the first network function, or

Fully Qualified Domain Name of the first network function.

15. The apparatus of claim 13 , wherein the first network function is a network function service consumer and the second network function is a network function service producer.

16. A method comprising:

generating, at a second apparatus configured to implement a first network function, a signature based on network function information, the network function information at least comprising identification information of the first network function, the signature specific to the first network function implemented by the second apparatus;

generating a message directed from the first network function to a second network function, the message comprising the signature and the network function information; and

transmitting the message to a first apparatus, the first apparatus configured to implement a service communication proxy connected to the first network function,

wherein the network function information further comprises at least one of:

certificate information of the first network function,

type information of the first network function, or

temporal information concerning transmission of the message, and

wherein the certificate information of the first network function comprises at least one of:

a client certificate of the first network function, or

an address which enables obtaining of a client certificate or a public key of the first network device.

17. The method of claim 16 , wherein the identification information of the first network function comprises at least one of:

an instance identifier of the first network function,

a set identifier of the first network function, or

Fully Qualified Domain Name of the first network function.

18. A first apparatus, configured to implement a service communication proxy connected to a first network function, the first apparatus comprising:

at least one processor; and

at least one memory including computer program codes;

the at least one memory and the computer program codes are configured to, with the at least one processor, cause the first apparatus to:

receive, from a second apparatus associated with the first network function, a message directed from the first network function to a second network function, the message comprising a first signature and network function information, the network function information at least comprising identification information of the first network function;

in accordance with a successful validation of the first signature, update the message with a second signature specific to the service communication proxy implemented by the first apparatus;

transmit the updated message to a third apparatus associated with the second network function, the updated message comprising at least the second signature and the network function information; and,

perform mutual authentication with the second apparatus associated with the first network function and with the third apparatus associated with the second network function.

19. A second apparatus configured to implement a first network function, the second apparatus comprising:

at least one processor; and

at least one memory including computer program codes;

the at least one memory and the computer program codes are configured to, with the at least one processor, cause the second apparatus to:

generate a signature based on network function information, the network function information at least comprising identification information of the first network function, the signature specific to the first network function implemented by the second apparatus;

generate a message directed from the first network function to a second network function, the message comprising the signature and the network function information;

transmit the message to a first apparatus, the first apparatus configured to implement a service communication proxy connected to the first network function; and,

perform mutual authentication with the service communication proxy connected to the first network function.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2021
From: BYKAMPADI, NAGENDRA; LANDAIS, BRUNO; HOLTMANNS, SILKE; EKMAN, JANI
To: NOKIA TECHNOLOGIES OY
Reel/Frame 055044/0831 →
Priority Claims (1)
IN 202041013502 · Mar 27, 2020 · national
Continuity (1)
Related Publication 20210306326A1 · Sep 30, 2021
References Cited (18)
US 20230131703A1 · Mahajan · 2023 [cited by examiner]
CN 206797564A · 2017 [cited by applicant]
EP 3709580A1 · 2020 [cited by examiner]
IN 201747005219A · 2017 [cited by applicant]
WO 02054665A1 · 2002 [cited by applicant]
WO WO2019163810A1 · 2019 [cited by examiner]
WO 2019193252A1 · 2019 [cited by applicant]
WO WO2019214942A1 · 2019 [cited by examiner]
Jaeduck Choi; Souhwan Jung; Kwangyong Bae; Hokun Moon; “A lightweight authentication and hop-by-hop security mechanism for SIP network”; 2008 International Conference on Advanced Technologies for Communications; Year: 2… [cited by examiner]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16)”, 3GPP TS 33.501, V16.1.0, Dec. 2019, pp. 1-202. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 16)”, 3GPP TS 29.500, V16.2.1, Jan. 2020, p… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 16)”, 3GPP TS 29.510, V16.2.0, Dec. 2019, pp. 1-167. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Principles and Guidelines for Services Definition; Stage 3 (Release 16)”, 3GPP TS 29.501, V16.2.0, Dec. 2019, pp.… [cited by applicant]
Fielding et al., “Hypertext Transfer Protocol (HTTP/1.1): Semantics and Content”, RFC 7231, Internet Engineering Task Force (IETF), Jun. 2014, pp. 1-101. [cited by applicant]
Petersson et al., “Forwarded HTTP Extension”, RFC 7239, Internet Engineering Task Force (IETF), Jun. 2014, pp. 1-16. [cited by applicant]
McGrew et al., “Cryptographic Algorithm Implementation Requirements and Usage Guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH)”, RFC 7321, Internet Engineering Task Force (IETF), Aug. 201… [cited by applicant]
Adams et al., “Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP)”, RFC 3161, Network Working Group, Aug. 2001, pp. 1-26. [cited by applicant]
Extended European Search Report received for corresponding European Patent Application No. 21156730.0, dated Aug. 3, 2021, 8 pages. [cited by applicant]
Cited By (1)
US 12,726,469