IP Library Granted Patent US 12,326,927
Granted Patent B2
US 12,326,927 · App. 18/023,216 · Granted Jun 10, 2025

System and method for automatic onboarding of network functions to a credential vault

Inventors: Akashdeep Chopra (Tokyo, JP); Manish Kumar (Tokyo, JP); Ashish Madan (Singapore, SG)
Assignee: RAKUTEN SYMPHONY, INC.
G06F21/44H04L9/3213H04L9/3247H04L9/3263G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,326,927
App. No.
18/023,216
Granted
Jun 10, 2025
Kind
B2
Abstract

To automatically onboard network functions to a credential vault, a orchestration processor actuates establishment of an cluster account for a network cluster, and actuates a cluster configuration of a processor of the vault to enable authentication of a network cluster. For each of a plurality of network functions associated with the network cluster, the orchestration processor generates an identifier, sets values for parameters of an initialization parameter set, actuates assignment of access permissions for a code address on a memory of the vault, actuates assignment of elevated access permissions for a credential address on the vault memory, and actuates association of the network function with a cluster account of the network cluster. The vault memory thereby defines credential addresses each corresponding to a respective network function.

Claims (72)

1. A method for onboarding of network functions to a credential vault, the credential vault including a vault memory and a vault processor, the vault memory storing an authentication code at a code address thereof, the method comprising, by at least one processor:

actuating establishment of an cluster account for a network cluster;

actuating a cluster configuration of the vault processor to enable authentication of the network cluster; and

for each network function of a plurality of network functions associated with the network cluster:

generating an identifier for the network function,

setting values for parameters of an initialization parameter set for the network function, the initialization parameter set including a credential address in the vault memory for storage of a credential for the network function, a value of the credential address being based on the generated identifier for the network function,

actuating assignment of access permissions to the network function for the code address on the vault memory,

actuating assignment of elevated access permissions to the network function for the credential address on the vault memory, and

actuating association of the network function with the cluster account of the network cluster;

the vault memory thereby defining a plurality of credential addresses each corresponding to a respective one of the plurality of network functions,

wherein the vault processor is configured to:

provide, based on receipt of a code retrieval request identifying the code address from a device having access permissions thereto, the authentication code,

store at a selected credential address, based on receipt of a credential storage request providing a credential and identifying the selected credential address from a device having elevated access permissions thereto, the provided credential, and

provide, based on receipt of a credential retrieval request identifying the selected credential address from a device having elevated access permissions thereto, the credential stored at the selected credential address.

2. The method of claim 1 , wherein the initialization parameter set further includes an identifier for the associated cluster, an account identifier of the network function for the associated cluster, an account identifier of the network function for the credential vault, and the code address in the vault memory.

3. The method of claim 2 , wherein the values for the account identifier of the network function for the associated cluster and the account identifier of the network function for the credential vault are based on the generated identifier for the network function.

4. The method of claim 1 , wherein the identifier for the network function is generated based on a concatenation of values reflecting features of the network function.

5. The method of claim 1 ,

wherein an authentication processor is configured to provide, based on receipt of a signature request including the authentication code, a signed authentication certificate, and

wherein the credential includes a private key and the signed authentication certificate.

6. The method of claim 5 ,

wherein the cluster configuration of the vault processor includes establishing access of an authentication token for the network cluster to the vault processor, and

wherein the signature request further includes the authentication token for the network cluster.

7. A non-transitory computer-readable recording medium having recorded thereon instructions executable by at least one processor to perform a method for onboarding of network functions to a credential vault, the credential vault comprising a vault memory and a vault processor, the vault memory storing an authentication code at a code address thereof, the method comprising:

actuating establishment of an cluster account for a network cluster;

actuating a cluster configuration of the vault processor to enable authentication of the network cluster; and

for each network function of a plurality of network functions associated with the network cluster:

generating an identifier for the network function,

setting values for parameters of an initialization parameter set for the network function, the initialization parameter set including a credential address in the vault memory for storage of a credential for the network function, a value of the credential address being based on the generated identifier for the network function,

actuating assignment of access permissions to the network function for the code address on the vault memory,

actuating assignment of elevated access permissions to the network function for the credential address on the vault memory, and

actuating association of the network function with the cluster account of the network cluster;

the vault memory thereby defining a plurality of credential addresses each corresponding to a respective one of the plurality of network functions,

wherein the vault processor is configured to:

provide, based on receipt of a code retrieval request identifying the code address from a device having access permissions thereto, the authentication code,

store at a selected credential address, based on receipt of a credential storage request providing a credential and identifying the selected credential address from a device having elevated access permissions thereto, the provided credential, and

provide, based on receipt of a credential retrieval request identifying the selected credential address from a device having elevated access permissions thereto, the credential stored at the selected credential address.

8. The recording medium of claim 7 , wherein the initialization parameter set further includes an identifier for the associated cluster, an account identifier of the network function for the associated cluster, an account identifier of the network function for the credential vault, and the code address in the vault memory.

9. The recording medium of claim 8 , wherein the values for the account identifier of the network function for the associated cluster and the account identifier of the network function for the credential vault are based on the generated identifier for the network function.

10. The recording medium of claim 7 , wherein the identifier for the network function is generated based on a concatenation of values reflecting features of the network function.

11. The recording medium of claim 7 ,

wherein an authentication processor is configured to provide, based on receipt of a signature request including the authentication code, a signed authentication certificate, and

wherein the credential includes a private key and the signed authentication certificate.

12. The recording medium of claim 11 ,

wherein the cluster configuration of the vault processor includes establishing access of an authentication token for the network cluster to the vault processor, and

wherein the signature request further includes the authentication token for the network cluster.

13. A system for onboarding of network functions to a credential vault, the system comprising:

an orchestrator, comprising at least one orchestration processor; and

the credential vault, comprising a vault memory and at least one vault processor,

wherein the vault memory stores an authentication code at a code address thereof,

wherein the at least one orchestration processor is configured to:

actuate establishment of an cluster account for a network cluster;

actuate a cluster configuration of the at least one vault processor to enable authentication of the network cluster; and

for each network function of a plurality of network functions associated with the network cluster:

generate an identifier for the network function,

set values for parameters of an initialization parameter set for the network function, the initialization parameter set including a credential address in the vault memory for storage of a credential for the network function, a value of the credential address being based on the generated identifier for the network function,

actuate assignment of access permissions to the network function for the code address on the vault memory,

actuate assignment of elevated access permissions to the network function for the credential address on the vault memory, and

actuate association of the network function with the cluster account of the network cluster;

the vault memory thereby defining a plurality of credential addresses each corresponding to a respective one of the plurality of network functions,

wherein the at least one vault processor is configured to:

provide, based on receipt of a code retrieval request identifying the code address from a device having access permissions thereto, the authentication code,

store at a selected credential address, based on receipt of a credential storage request providing a credential and identifying the selected credential address from a device having elevated access permissions thereto, the provided credential, and

provide, based on receipt of a credential retrieval request identifying the selected credential address from a device having elevated access permissions thereto, the credential stored at the selected credential address.

14. The system of claim 13 , wherein the initialization parameter set further includes an identifier for the associated cluster, an account identifier of the network function for the associated cluster, an account identifier of the network function for the credential vault, and the code address in the vault memory.

15. The system of claim 14 , wherein the values for the account identifier of the network function for the associated cluster and the account identifier of the network function for the credential vault are based on the generated identifier for the network function.

16. The system of claim 13 , wherein the identifier for the network function is generated based on a concatenation of values reflecting features of the network function.

17. The system of claim 13 , further comprising an authentication server, the authentication server comprising at least one authentication processor configured to provide, based on receipt of a signature request including the authentication code, a signed authentication certificate,

wherein the credential includes a private key and the signed authentication certificate.

18. The system of claim 17 ,

wherein the cluster configuration of the at least one vault processor includes establishing access of an authentication token for the network cluster to the at least one vault processor, and

wherein the signature request further includes the authentication token for the network cluster.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2024
From: RAKUTEN SYMPHONY SINGAPORE PTE LTD
To: RAKUTEN SYMPHONY, INC.
Reel/Frame 068466/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: CHOPRA, AKASHDEEP; KUMAR, MANISH; MADAN, ASHISH
To: RAKUTEN SYMPHONY, INC.; RAKUTEN SYMPHONY SINGAPORE PTE. LTD.
Reel/Frame 062799/0309 →
Continuity (1)
Related Publication 20250077638A1 · Mar 6, 2025
References Cited (7)
US 20180027073A1 · Kazi · 2018 [cited by applicant]
US 20180191581A1 · Yu · 2018 [cited by examiner]
US 20180359100A1 · Gaddam et al. · 2018 [cited by applicant]
US 20200007335A1 · Tan · 2020 [cited by examiner]
US 20200042731A1 · Kim · 2020 [cited by examiner]
International Search Report dated Mar. 22, 2023, issued in International Application No. PCT/US2022/053676. [cited by applicant]
Written Opinion dated Mar. 22, 2023, issued in International Application No. PCT/US2022/053676. [cited by applicant]