IP Library › Granted Patent US 12,519,660
Granted Patent B2
US 12,519,660 · App. 18/113,041 · Granted Jan 6, 2026

Methods, systems, and computer readable media for protecting against unauthorized use of certificate management protocol (CMP) client identity private keys and public key certificates associated with network functions

Inventors: Jay Rajput (Bangalore, IN); Virendra Singh (Bangalore, IN); Pavani Chirala (Sadananda Nagar, IN)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04L9/3268H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,660
App. No.
18/113,041
Granted
Jan 6, 2026
Kind
B2
Abstract

A method for protecting against unauthorized use of CMP client identity private keys and CMP public key certificates associated with NFs includes receiving, by a CMP CA proxy, a first CMP certificate request for renewing a security certificate associated with a first NF, the CMP certificate request including a public key certificate associated with the first NF and is protected by a CMP client identity private key associated with the first NF. The method further includes determining that the first NF is registered with the NRF, and, in response to determining that the first NF is registered with the NRF, checking, by the CMP CA proxy whether the first CMP certificate request includes an NRF-issued access token for the first NF, determining that the CMP certificate request does not include the NRF-issued access token for the first NF, and, in response to determining that the first CMP certificate request does not include the NRF-issued access token for the first NF, performing a network security action regarding the first CMP certificate request.

Claims (43)

1 . A method for protecting against unauthorized use of certificate management protocol (CMP) client identity private keys and CMP public key certificates associated with network functions (NFs), the method comprising:

receiving, by a CMP certificate authority (CA) proxy, a first CMP certificate request for renewing a security certificate associated with a first NF, the CMP certificate request including a public key certificate associated with the first NF and is protected by a CMP client identity private key associated with the first NF, wherein receiving the first CMP certificate request includes receiving the first CMP certificate request from a hacker impersonating the first NF;

checking, by the CMP CA proxy, whether the first NF is registered with an NF repository function (NRF) and determining that the first NF is registered with the NRF;

in response to determining, by the CMP CA proxy that the first NF is registered with the NRF, determining, by the CMP CA proxy, whether the first CMP certificate request includes an OAuth 2.0 access token of the first NF that consumer NFs present to the first NF to access services provided by the first NF; and

in response to determining, by the CMP CA proxy, that the first CMP certificate request does not include the OAuth 2.0 access token of the first NF, performing a network security action regarding the first CMP certificate request, wherein performing the network security action for the first CMP certificate request includes preventing a CMP CA from providing the security certificate to the hacker by blocking the first CMP certificate request-from being sent by the CMP CA proxy to the CMP CA.

2 . The method of claim 1 wherein receiving the first CMP certificate request at the CMP CA proxy includes receiving the first CMP certificate request at the CMP CA proxy that is a component of the NRF or at the CMP CA proxy that is separate from the NRF.

3 . The method of claim 1 wherein receiving the first CMP certificate request includes intercepting the first CMP certificate request.

4 . The method of claim 1 wherein receiving the first CMP certificate request includes receiving the first CMP certificate request for a transport layer security (TLS) or a client credentials assertion (CCA) certificate of the first NF.

5 . The method of claim 1 comprising:

receiving, by the CMP CA proxy, a second CMP certificate request for renewing a security certificate associated with a second NF, the request including a public key certificate associated with the second NF and is protected by a CMP client identity private key associated with the second NF;

checking, by the CMP CA proxy, whether the second NF is registered with the NRF and determining that the second NF is not registered with the NRF; and

in response to determining that the second NF is not registered with the NRF, allowing processing of the second CMP certificate request.

6 . The method of claim 5 wherein allowing processing of the second CMP certificate request includes providing the second CMP certificate request to the CMP CA, at the CMP CA, generating a CMP certificate response including the security certificate associated with the second NF, and forwarding the CMP certificate response to an originator of the second CMP certificate request.

7 . The method of claim 1 comprising:

transmitting, by a second NF and to the CMP CA proxy, a second CMP certificate request for renewing a second security certificate associated with the second NF, the second CMP certificate request including a public key certificate and an NRF-issued OAuth 2.0 access token associated with the second NF;

receiving, by the CMP CA proxy, the second CMP certificate request;

checking, by the CMP CA proxy, whether the second NF is registered with the NRF and determining that the second NF is registered with the NRF;

in response to determining, by the CMP CA proxy that the second NF is registered with the NRF, checking, by the CMP CA proxy whether the second CMP certificate request includes the NRF-issued OAuth 2.0 access token associated with the second NF and determining that the second CMP certificate request includes the NRF-issued OAuth 2.0 access token associated with the second NF; and

in response to determining, by the CMP CA proxy, that the second CMP certificate request includes the NRF-issued OAuth 2.0 access token associated with the second NF, allowing processing of the second CMP certificate request by forwarding the second CMP certificate request to a CMP CA proxy.

8 . A system for protecting against unauthorized use of certificate management protocol (CMP) client identity private keys and CMP public key certificates associated with network functions (NFs), the system comprising:

a CMP certificate authority (CA) proxy including at least one processor and a memory; and

a CMP certificate request validator implemented by the at least one processor for:

receiving a first CMP certificate request for renewing a security certificate associated with a first NF, the CMP certificate request including a public key certificate associated with the first NF and is protected by a CMP client identity private key associated with the first NF, wherein receiving the first CMP certificate request includes receiving the first CMP certificate request from a hacker impersonating the first NF;

checking whether the first NF is registered with an NF repository function (NRF) and determining that the first NF is registered with the NRF;

in response to determining that the first NF is registered with the NRF, determining whether the first CMP certificate request includes an OAuth 2.0 access token of the first NF that consumer NFs present to the first NF to access services provided by the first NF; and

in response to determining that the first CMP certificate request does not include the OAuth 2.0 access token of the first NF, performing a network security action regarding the first CMP certificate request, wherein performing the network security action comprises preventing a CMP CA from providing the security certificate to the hacker by blocking the first CMP certificate request from being sent by the CMP CA proxy to the CMP CA.

9 . The system of claim 8 wherein the CMP CA proxy comprises a component of the NRF or is separate from the NRF.

10 . The system of claim 8 wherein the CMP CA proxy is configured to receive the first CMP certificate request by intercepting the first CMP certificate request.

11 . The system of claim 8 wherein the security certificate comprises a transport layer security (TLS) or a client credentials assertion (CCA) certificate of the first NF.

12 . The system of claim 8 wherein the CMP certificate request validator is configured to:

receive a second CMP certificate request for renewing a security certificate associated with a second NF, the request including a public key certificate associated with the second NF and is protected by a CMP client identity private key associated with the second NF;

check whether the second NF is registered with the NRF and determine that the second NF is not registered with the NRF; and

in response to determining that the second NF is not registered with the NRF, allow processing of the second CMP certificate request.

13 . The system of claim 8 comprising a second NF for transmitting, to the CMP CA proxy, a second CMP certificate request for renewing a second security certificate associated with the second NF, the second CMP certificate request including a public key certificate associated with the second NF, is protected by a CMP client identity private key associated with the second NF, and includes an NRF-issued OAuth 2.0 access token associated with the second NF, wherein the CMP certificate request validator is configured to:

receive the second CMP certificate request;

check whether the second NF is registered with the NRF and determining that the second NF is registered with the NRF;

in response to determining that the second NF is registered with the NRF, check whether the second CMP certificate request includes the NRF-issued OAuth 2.0 access token associated with the second NF and determine that the second CMP certificate request includes the NRF-issued OAuth 2.0 access token associated with the second NF; and

in response to determining that the second CMP certificate request includes the NRF-issued OAuth 2.0 access token associated with the second the second NF, allowing processing of the second CMP certificate request by forwarding the second CMP certificate request to the CMP CA.

14 . A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising:

receiving, by a certificate management protocol (CMP) certificate authority (CA) proxy, a first CMP certificate request for renewing a security certificate associated with a first network function (NF), the CMP certificate request including a public key certificate associated with the first NF and is protected by a CMP client identity private key associated with the first NF, wherein receiving the first CMP certificate request includes receiving the first CMP certificate request from a hacker impersonating the first NF;

checking, by the CMP CA proxy, whether the first NF is registered with an NF repository function (NRF) and determining that the first NF is registered with the NRF;

in response to determining, by the CMP CA proxy that the first NF is registered with the NRF, determining whether the first CMP certificate request includes an OAuth 2.0 access token of the first NF that consumer NFs present to the first NF to access services provided by the first NF; and

in response to determining, by the CMP CA proxy, that the first CMP certificate request does not include the OAuth 2.0 access token of the first NF, performing a network security action regarding the first CMP certificate request, wherein performing the network security action comprises preventing a CMP CA from providing the security certificate to the hacker by blocking the first CMP certificate request-from being sent by the CMP CA proxy to the CMP CA.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2023
From: RAJPUT, JAY; CHIRALA, PAVANI; SINGH, VIRENDRA
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 062830/0218 →
Continuity (1)
Related Publication 20240283661A1 · Aug 22, 2024
References Cited (39)
US 9331990B2 · Le Saint · 2016 [cited by applicant]
US 10075435B1 · Byrd et al. · 2018 [cited by applicant]
US 10903999B1 · Raman et al. · 2021 [cited by applicant]
US 11522721B2 · Choyi · 2022 [cited by examiner]
US 20210288802A1 · Muhanna · 2021 [cited by examiner]
US 20210314171A1 · Choyi · 2021 [cited by examiner]
US 20210377053A1 · Mahajan · 2021 [cited by examiner]
US 20210377054A1 · Mahajan · 2021 [cited by examiner]
US 20220086734A1 · Aggarwal et al. · 2022 [cited by applicant]
US 20220210624A1 · Ping et al. · 2022 [cited by applicant]
US 20220345486A1 · Rajput et al. · 2022 [cited by applicant]
US 20230064698A1 · Choyi et al. · 2023 [cited by applicant]
US 20230412396A1 · Bommisetty · 2023 [cited by examiner]
US 20240121111A1 · Gomez · 2024 [cited by examiner]
US 20240414144A1 · Chirala et al. · 2024 [cited by applicant]
WO WO2021008716A1 · 2021 [cited by examiner]
WO WO2021099675A1 · 2021 [cited by examiner]
WO WO2023242058A1 · 2023 [cited by examiner]
WO WO2024094319A1 · 2024 [cited by examiner]
Hardt, “The OAuth 2.0 Authorization Framework”, Internet Engineering Task Force (IETF), RFC 6749, pp. 1-76 (Oct. 2012). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP TS 33.501, V17.8.0, pp. 1-292 (Dec. 2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 18)”, 3GPP TS 29.510, V18.1.0, pp. 1-330 (Dec. 2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Principles and Guideline for Services Definition; Stage 3 (Release 18)”, 3GPP TS 29.501, V18.0.0, pp. 1-83 (Dec. … [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 18)”, 3GPP TS 29.500, V18.0.0, pp. 1-131 (D… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 17)”, 3GPP TS 29.510, V17.5.0, pp. 1-298 (Mar. 2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP TS 33.501, V17.7.0, pp. 1-292 (Sep. 2022). [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Principles and Guideline for Services Definition; Stage 3 (Release 17)”, 3GPP TS 29.501, V17.7.0, pp. 1-81 (Sep. … [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 17)”, 3GPP TS 29.500, V17.8.0, pp. 1-131 (S… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 17)”, 3GPP TS 23.502, V17.6.0, pp. 1-748 (Sep. 2022). [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (5GS); Stage 2 (Release 17), 3GPP TS 23.501, V17.6.0, pp. 1-571 (Sep. 202… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Network Domain Security (NDS); Authentication Framework (AF) (Release 18) 3GPP TS 33.310 V18.0.0 pp. 1-61 (Mar. 2023). [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 18) 3GPP TS 33.501 V18.0.0 pp. 1-252 (Dec. 2022). [cited by applicant]
Commonly-Assigned, co-pending U.S. Appl. No. 18/207,117 for Methods, Systems, and Computer Readable Media for Automatically Binding a Service-Based Interface (SBI) Communications Digital Certificate Lifecycle To a Netwo… [cited by applicant]
Cooper, et al., “Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile”, IETF RFC 5280 (May 2008). [cited by applicant]
Adams, et al., “Internet X.509 Public Key Infrastructure Certificate Management Protocol (CMP)”, IETF RFC 4210 (Sep. 2005). [cited by applicant]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration for International Patent Application Serial No. PCT/US2024/013622 (May … [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/207,117 (Mar. 20, 2025). [cited by applicant]
Final Office Action for U.S. Appl. No. 18/207,117 (Aug. 1, 2025). [cited by applicant]
Advisory Action for U.S. Appl. No. 18/207,117 (Nov. 10, 2025). [cited by applicant]
Cited By (1)
US 12,580,905