IP Library Patent Application 18215771
Patent Application
App. No. 18/215,771

ACCESS CONTROL IN A RAN

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/215,771
Abstract

Some embodiments of the invention provide a method for implementing access controls in a RAN (radio access network) to limit access to base station components of the RAN by RAN applications. The method is performed at a RIC (RAN intelligent controller) that connects the RAN applications to the base station components. The method receives a set of access control data that specifies which RAN applications are allowed to access which base station components. For each particular RAN application, the method (1) identifies, from the set of access control data, a particular subset of access control data that specifies at least one particular base station component accessible to the particular RAN application, and (2) provides the particular subset of access control data to the particular RAN application to enable the particular RAN application to send data messages to the at least one particular base station component.

Claims (45)

1 . A method of implementing access controls in a RAN (radio access network) to limit access to a plurality of base station components of the RAN by a plurality of RAN applications, the method comprising:

at a RIC (RAN intelligent controller) that connects the plurality of RAN applications to the plurality of base station components:

receiving a set of access control data that specifies which RAN applications in the plurality of RAN application are allowed to access which base station components in the plurality of base station components;

for each particular RAN application in the plurality of RAN applications,

identifying, from the set of access control data, a particular subset of access control data that specifies at least one particular base station component accessible to the particular RAN application; and

providing the particular subset of access control data to the particular RAN application to enable the particular RAN application to send data messages to the at least one particular base station component.

2 . The method of claim 1 , wherein:

each particular RAN application executes on a particular machine;

a particular interface is implemented on each particular machine to facilitate communications between the particular RAN application and the RIC; and

providing the particular subset of access control data to the particular RAN application comprises providing the particular subset of access control data to the particular interface.

3 . The method of claim 2 , wherein the particular interface comprises a particular SDK (software development kit).

4 . The method of claim 3 , wherein said receiving, using, and forwarding are performed by a datapath pod of the RIC that forwards traffic between the plurality of RAN applications and the plurality of base station components, wherein the particular SDK connects the particular RAN application to the datapath pod and receives the subset of access control data from the datapath pod.

5 . The method of claim 4 , wherein:

the datapath pod is one of a plurality of datapath pods of the RIC; and

the particular SDK is an enhanced particular SDK that connects the particular RAN application to each datapath pod in the plurality of datapath pods of the RIC.

6 . The method of claim 1 further comprising:

receiving, from a first RAN application in the plurality of RAN applications, a data message destined for a first base station component in the plurality of base station components; and

using the set of access control data to determine whether the first RAN application is allowed to access the first base station component.

7 . The method of claim 6 , wherein when, based on the set of access control data, the first RAN application is not allowed to access the first base station component, the method further comprises sending a notification to the first RAN application indicating the first RAN application is not allowed to access the first base station component.

8 . The method of claim 6 , wherein when, based on the set of access control data, the first RAN application is allowed to access the first base station component, the method further comprises forwarding the data message to the first base station component.

9 . The method of claim 8 , wherein the data message is a first data message, the method further comprising:

receiving an updated set of access control data that indicates the first RAN application's access to the first base station component has been revoked;

before providing an updated subset of access control data to the first RAN application, receiving a second data message from the first RAN application destined to the first base station component; and

based on the updated set of access control data, sending a notification to the first RAN application indicating the first RAN application is not allowed to access the first base station component.

10 . The method of claim 1 , wherein the set of access control data comprises (i) a set of access control lists, each access control list specifying a particular set of accessible base station components, and (ii) a set of access maps that specify, for each access control list, one or more RAN applications in the plurality of RAN applications for which the access control list is applicable.

11 . The method of claim 10 , wherein each base station component in the plurality of base station components comprises one or more RAN functions, wherein each access control list in the set of access control lists further specifies one or more operations that can be performed against the one or more RAN functions of each base station component in the particular set of base station components specified by the access control list.

12 . The method of claim 11 , wherein the one or more operations comprise one or more operations from a set of operations comprising (i) an insert operation for instructing the one or more RAN functions to activate a user plane function, (ii) a reporting operation for receiving reports from the one or more RAN functions, (iii) a policy operation for setting a policy parameter for the one or more RAN functions, and (iv) a control operation for instructing the one or more RAN functions to activate a control plane function.

13 . The method of claim 11 , wherein the one or more operations are defined in access profiles, each access profile comprising (i) a unique identifier assigned to the access profile, (ii) a unique name assigned to the access profile, and (iii) a set of access rules specifying the one or more operations.

14 . The method of claim 13 , wherein each access list in the set of access lists specifies the one or more operations by specifying a unique identifier assigned to an access profile that defines the one or more operations.

15 . The method of claim 1 , wherein: the base station components comprise centralized units (CUs) and distributed units (DUs).

16 . A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for implementing access controls in a RAN (radio access network) to limit access to a plurality of base station components of the RAN by a plurality of RAN applications, the program comprising sets of instructions for:

at a RIC (RAN intelligent controller) that connects the plurality of RAN applications to the plurality of base station components:

receiving a set of access control data that specifies which RAN applications in the plurality of RAN application are allowed to access which base station components in the plurality of base station components;

for each particular RAN application in the plurality of RAN applications,

identifying, from the set of access control data, a particular subset of access control data that specifies at least one particular base station component accessible to the particular RAN application; and

providing the particular subset of access control data to the particular RAN application to enable the particular RAN application to send data messages to the at least one particular base station component.

17 . The non-transitory machine readable medium of claim 16 , wherein:

each particular RAN application executes on a particular machine;

a particular interface is implemented on each particular machine to facilitate communications between the particular RAN application and the RIC; and

the set of instructions for providing the particular subset of access control data to the particular RAN application comprises a set of instructions for providing the particular subset of access control data to the particular interface.

18 . The non-transitory machine readable medium of claim 17 , wherein the particular interface comprises a particular SDK (software development kit).

19 . The non-transitory machine readable medium of claim 18 , wherein said receiving, using, and forwarding are performed by a datapath pod of the RIC that forwards traffic between the plurality of RAN applications and the plurality of base station components, wherein the particular SDK connects the particular RAN application to the datapath pod and receives the subset of access control data from the datapath pod.

20 . The method of claim 19 , wherein:

the datapath pod is one of a plurality of datapath pods of the RIC; and

the particular SDK is an enhanced particular SDK that connects the particular RAN application to each datapath pod in the plurality of datapath pods of the RIC.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: SINGH, AMIT
To: VMWARE, INC.
Reel/Frame 064883/0413 →