IP Library › Granted Patent US 11,855,977
Granted Patent B2
US 11,855,977 · App. 18/045,890 · Granted Dec 26, 2023

Systems and methods for configuring a network function proxy for secure communication

Inventors: Amit Mahajan (Bridgewater, NJ); Jayesh Kumar Laad (Ashland, MA); John M. Bittenbender (Bloomsburg, PA)
Assignee: Verizon Patent and Licensing Inc.
H04L63/0823H04L9/3268H04L47/82H04L63/0281H04L63/0869H04L63/166H04L67/56H04L2209/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,855,977
App. No.
18/045,890
Granted
Dec 26, 2023
Kind
B2
Abstract

A device may determine that a network function of a network is to use a secure communication protocol. The network function may be configured to facilitate communication via the network. The device may identify a component of a resource configuration that is to instantiate the network function. The device may instantiate, using the component, a proxy for the network function. The device may configure the proxy to obtain a certificate that is associated with the secure communication protocol. The device may cause the proxy to use the certificate to communicate with another proxy that is associated with the network function to perform an operation associated with the network function.

Claims (58)

1. A method, comprising:

instantiating, by a device, a virtual network function for a communication session with a user equipment (UE);

instantiating, by the device, a distributed proxy associated with the virtual network function;

receiving, by the device, a certificate signing request from the distributed proxy;

obtaining, by the device and from a certificate authority of a public key infrastructure, a certificate for the distributed proxy based on the certificate signing request;

generating, by the device, a certificate profile for the distributed proxy based on obtaining the certificate;

providing, by the device, the certificate profile to the distributed proxy to enable the virtual network function to utilize the certificate to communicate with the UE via the communication session; and

authenticating the virtual network function based on receiving the certificate signing request from the distributed proxy.

2. The method of claim 1 , wherein authenticating the virtual network function comprises:

determining that the virtual network function is instantiated by the device; and

authenticating the virtual network function based on the virtual network function being instantiated by the device.

3. The method of claim 1 , wherein authenticating the virtual network function comprises:

determining that the distributed proxy is associated with the virtual network function; and

authenticating the virtual network function based on the distributed proxy being associated with the virtual network function.

4. The method of claim 1 , further comprising:

determining that a quantity of communication sessions associated with a network satisfies a threshold quantity of communication sessions.

5. The method of claim 4 , wherein the virtual network function is instantiated based on the quantity of communication sessions associated with the network satisfying the threshold quantity of communication sessions.

6. The method of claim 1 , wherein the distributed proxy includes a master proxy and a plurality of proxies associated with respective components of the virtual network function, and wherein the master proxy utilizes the certificate to securely communicate data between components of the virtual network function via the plurality of proxies.

7. The method of claim 1 , wherein the distributed proxy includes a master proxy and a plurality of proxies associated with respective components of the virtual network function, and wherein the master proxy utilizes the certificate to issue certificates to the plurality of proxies to enable a secure communication of data between the respective components of the virtual network function via the plurality of proxies.

8. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

instantiate a virtual network function for a communication session with a user equipment (UE);

instantiate a distributed proxy associated with the virtual network function;

receive a certificate signing request from the distributed proxy;

obtain, from a certificate authority of a public key infrastructure, a certificate for the distributed proxy based on the certificate signing request;

generate a certificate profile for the distributed proxy based on obtaining the certificate;

provide the certificate profile to the distributed proxy to enable the virtual network function to utilize the certificate to communicate with the UE via the communication session; and

authenticate the virtual network function based on receiving the certificate signing request from the distributed proxy.

9. The non-transitory computer-readable medium of claim 8 , wherein the one or more instructions, that cause the device to authenticate the virtual network function, cause the device to:

determine that the virtual network function is instantiated by the device; and

authenticate the virtual network function based on the virtual network function being instantiated by the device.

10. The non-transitory computer-readable medium of claim 8 , wherein the one or more instructions, that cause the device to authenticate the virtual network function, cause the device to:

determine that the distributed proxy is associated with the virtual network function; and

authenticate the virtual network function based on the distributed proxy being associated with the virtual network function.

11. The non-transitory computer-readable medium of claim 8 , wherein the one or more instructions further cause the device to:

determine that a quantity of communication sessions associated with a network satisfies a threshold quantity of communication sessions.

12. The non-transitory computer-readable medium of claim 11 , wherein the virtual network function is instantiated based on the quantity of communication sessions associated with the network satisfying the threshold quantity of communication sessions.

13. The non-transitory computer-readable medium of claim 8 , wherein the distributed proxy includes a master proxy and a plurality of proxies associated with respective components of the virtual network function, and wherein the master proxy utilizes the certificate to securely communicate data between components of the virtual network function via the plurality of proxies.

14. The non-transitory computer-readable medium of claim 8 , wherein the distributed proxy includes a master proxy and a plurality of proxies associated with respective components of the virtual network function, and wherein the master proxy utilizes the certificate to issue certificates to the plurality of proxies to enable a secure communication of data between the respective components of the virtual network function via the plurality of proxies.

15. A device, comprising:

one or more hardware processors configured to:

instantiate a virtual network function for a communication session with a user equipment (UE);

instantiate a distributed proxy associated with the virtual network function;

receive a certificate signing request from the distributed proxy;

obtain, from a certificate authority of a public key infrastructure, a certificate for the distributed proxy based on the certificate signing request;

generate a certificate profile for the distributed proxy based on obtaining the certificate;

provide the certificate profile to the distributed proxy to enable the virtual network function to utilize the certificate to communicate with the UE via the communication session; and

authenticate the virtual network function based on receiving the certificate signing request from the distributed proxy.

16. The device of claim 15 , wherein the one or more processors, to authenticate the virtual network function, are configured to:

determine that the virtual network function is instantiated by the device; and

authenticate the virtual network function based on one or more of:

the virtual network function being instantiated by the device, or

the distributed proxy being associated with the virtual network function.

17. The device of claim 15 , wherein the one or more processors are further configured to:

determine that a quantity of communication sessions associated with a network satisfies a threshold quantity of communication sessions.

18. The device of claim 7 , wherein the virtual network function is instantiated based on the quantity of communication sessions associated with the network satisfying the threshold quantity of communication sessions.

19. The device of claim 15 , wherein the distributed proxy includes a master proxy and a plurality of proxies associated with respective components of the virtual network function, and wherein the master proxy utilizes the certificate to securely communicate data between components of the virtual network function via the plurality of proxies.

20. The device of claim 15 , wherein the distributed proxy includes a master proxy and a plurality of proxies associated with respective components of the virtual network function, and wherein the master proxy utilizes the certificate to issue certificates to the plurality of proxies to enable a secure communication of data between the respective components of the virtual network function via the plurality of proxies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2022
From: MAHAJAN, AMIT; LAAD, JAYESH KUMAR; BITTENBENDER, JOHN M.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 061392/0660 →
Continuity (2)
Continuation 16883577 · May 26, 2020
Related Publication 20230131703A1 · Apr 27, 2023