IP Library Granted Patent US 12,494,899
Granted Patent B2
US 12,494,899 · App. 18/312,627 · Granted Dec 9, 2025

Apparatus, methods, and computer programs for protecting sensitive data

Inventors: Chaitanya Aggarwal (Munich, DE); Saurabh Khare (Bangalore, IN); German Peinado Gomez (Warsaw, PL)
Assignee: NOKIA TECHNOLOGIES OY
H04L9/0822G06F21/6209H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,494,899
App. No.
18/312,627
Granted
Dec 9, 2025
Kind
B2
Abstract

There is provided a method, computer program, and an apparatus for a network function service consumer, that causes the apparatus to perform: retrieving, from a first repository function, protected sensitive data; retrieving, from a second network function, at least one encrypted key; decrypting the retrieved at least one encrypted key using a private key associated with the network function service consumer to obtain a respective at least one key; and performing at least one of: decryption of the protected sensitive data using the at least one key to obtain sensitive data or integrity protected sensitive data; or verification of the integrity of the protected sensitive data using the at least one key.

Claims (67)

1 . An apparatus for a network function service consumer, the apparatus comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:

retrieve, from a first repository function, protected sensitive data, wherein the sensitive data comprises a machine learning model;

retrieve, from a second network function, at least one encrypted key, wherein the at least one encrypted key comprises an encrypted first key for integrity verification of the protected sensitive data;

decrypt the retrieved at least one encrypted key using a private key associated with the network function service consumer to obtain a respective at least one key; and

at least one of:

decrypt the protected sensitive data using the at least one key to obtain sensitive data or integrity protected sensitive data; or

verify the integrity of the protected sensitive data using the at least one key.

2 . The apparatus of claim 1 , wherein the at least one memory and the instructions are configured to, with the at least one processor, further cause the apparatus to:

obtain, from a network repository function, an access token for authorising the apparatus to have access to the protected sensitive data;

provide the access token to the first repository function as part of a service request for the protected sensitive data; and

receive the protected sensitive data in response to said providing.

3 . The apparatus of claim 2 , wherein the receiving the protected sensitive data comprises:

receive an address from which the protected sensitive data may be downloaded; and

download the protected sensitive data from the address.

4 . The apparatus of claim 2 , wherein the at least one memory and the instructions are configured to, with the at least one processor, further cause the apparatus to:

receive, from the first repository function, at least one of:

an indication that the protected sensitive data is encrypted;

an indication that the second network function comprises a key for decrypting the protected sensitive data;

an indication that the protected sensitive data is integrity protected; or

an indication that the second network function comprises a key and/or metadata associated with verifying the protected sensitive data.

5 . The apparatus of claim 2 , wherein the at least one memory and the instructions are configured to, with the at least one processor, further cause the apparatus to:

signal, to a network repository function, a request for the access token; wherein

the request comprises an indication that the apparatus is configured to decrypt and/or verify protected sensitive data, and either a public key or an indication of where to obtain the public key; and wherein

the public key is a public key of the network function service consumer to be used for encrypting the at least one key.

6 . The apparatus of claim 5 , wherein the indication of where to obtain the public key comprises one of the following:

from a transport layer security, TLS, certificate; or

from a client credentials assertion, CCA.

7 . The apparatus of claim 1 , wherein the second network function is a network repository function.

8 . The apparatus of claim 1 , wherein the second network function is a network function service producer and/or a network analytics data function.

9 . The apparatus of claim 1 , wherein the at least one encrypted key further comprises:

an encrypted second key for decrypting the protected sensitive data.

10 . An apparatus for a network function service producer, the apparatus comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:

protect sensitive data using at least one key to form protected sensitive data, wherein the sensitive data comprises a machine learning model, and wherein the at least one key comprises an encrypted first key for integrity verification of the protected sensitive data;

register the protected sensitive data at a first repository function; and

provide the at least one key to a network function.

11 . The apparatus of claim 10 , wherein the providing the at least one key to a network function comprises:

provide the at least one key to a network repository function.

12 . The apparatus of claim 10 , wherein the providing the at least one key to a network function comprises:

receive a request for the at least one key from a network function service consumer;

encrypt the at least one key using a public key associated with the network function service consumer to form at least one encrypted key; and

provide the at least one encrypted key to the network function service consumer.

13 . The apparatus of claim 10 , wherein the request for the at least one key comprises the public key or an indication of where to obtain the public key.

14 . The apparatus of claim 13 , wherein the indication of where to obtain the public key comprises an indication of one of the following:

from a transport layer security, TLS, certificate; or

from a client credentials assertion, CCA.

15 . The apparatus of claim 10 , wherein the at least one key further comprises:

an encrypted second key for decrypting the protected sensitive data.

16 . The apparatus of claim 10 , wherein the at least one memory and the instructions are configured to, with the at least one processor, further cause the apparatus to:

register a profile for the network function service producer at a network repository function, wherein the profile comprises an indication that the network function service producer is able to provide the at least one key to the network function.

17 . An apparatus for a network repository function, the apparatus comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:

store profile information for a first network function service producer, wherein the profile comprises an indication that the first network function service producer is able to provide at least one first key associated with verifying and/or decrypting a first protected sensitive data to another network function, wherein the first sensitive data comprises a machine learning model;

receive, from a first network function service consumer, a request for a first access token for enabling the first network function service consumer to obtain the at least one first key;

provide the first network function service consumer with the requested access token;

receive, from a second network function service producer, at least one second key associated with verifying and/or decrypting a second protected sensitive data, wherein the at least one second key comprises an encrypted key for integrity verification of the protected sensitive data; and

receive, from a second network function service consumer, a request for a second access token for accessing the second protected sensitive data, wherein

the request for the second access token comprises an indication that the second network function service consumer is configured to decrypt and/or verify protected sensitive data, and either a public key or an indication of where to obtain the public key; and wherein

the public key is a public key of the second network function service consumer;

encrypt the at least one second key using the public key to form at least one encrypted second key; and

provide the at least one encrypted second key to the network function service consumer.

18 . The apparatus of claim 17 , wherein the at least one encrypted second key is provided as part of an access token claim in response to the request for the access token.

19 . The apparatus of claim 17 , wherein the at least one second key further comprises an encrypted key for decrypting the protected sensitive data.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2024
From: AGGARWAL, CHAITANYA
To: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
Reel/Frame 066092/0022 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2024
From: GOMEZ, GERMAN PEINADO
To: NOKIA SOLUTIONS AND NETWORKS SP. Z.O.O
Reel/Frame 066092/0768 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2024
From: KHARE, SAURABH
To: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
Reel/Frame 066092/0905 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2024
From: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
To: NOKIA TECHNOLOGIES OY
Reel/Frame 066093/0005 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2024
From: NOKIA SOLUTIONS AND NETWORKS SP. Z.O.O
To: NOKIA TECHNOLOGIES OY
Reel/Frame 066093/0075 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2024
From: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
To: NOKIA TECHNOLOGIES OY
Reel/Frame 066093/0113 →
Priority Claims (1)
IN 202241026450 · May 6, 2022 · national
Continuity (1)
Related Publication 20230361989A1 · Nov 9, 2023
References Cited (25)
US 9692789B2 · Kirti et al. · 2017 [cited by applicant]
US 11188785B2 · Lee et al. · 2021 [cited by applicant]
US 20020002047A1 · Fujiwara · 2002 [cited by examiner]
US 20030028773A1 · McGarvey · 2003 [cited by examiner]
US 20030051129A1 · Razdan · 2003 [cited by examiner]
US 20070136606A1 · Mizuno · 2007 [cited by examiner]
US 20090276829A1 · Sela · 2009 [cited by examiner]
US 20100099511A1 · Stites · 2010 [cited by examiner]
US 20160072772A1 · Geigel · 2016 [cited by examiner]
US 20180234403A1 · Casella et al. · 2018 [cited by applicant]
US 20210118547A1 · Morris · 2021 [cited by examiner]
US 20220053348A1 · Singh et al. · 2022 [cited by applicant]
WO 2021018460A1 · 2021 [cited by applicant]
WO 2021136601A1 · 2021 [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP TS 33.501, V17.5.0, Mar. 2022, pp. 1-293. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Architecture enhancements for 5G System (5GS) to support network data analytics services (Release 17)”, 3GPP TS 23.288, V17… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study of Enablers for Network Automation for 5G System (5GS); Phase 3 (Release 18)”, 3GPP TR 23.700-81, V0.1.0, Mar. 2022, … [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Technical Realization of Service Based Architecture; Stage 3 (Release 17)”, 3GPP TS 29.500, V17.6.0, Mar. 2022, p… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Function Repository Services; Stage 3 (Release 17)”, 3GPP TS 29.510, V17.5.0, Mar. 2022, pp. 1-298. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enablers for Network Automation for 5G—phase 3; (Release 18)”, 3GPP TR 33.738, V1.0.0, Mar. 20… [cited by applicant]
“Resolution of EN related to encryption in KI#3 conclusion in eNA_SEC_Ph3”, 3GPP TSG-SA3 Meeting #110Ad-Hoc-e, S3-232151, Agenda: 5.8, Nokia, Apr. 17-21, 2023, 2 pages. [cited by applicant]
Extended European Search Report received for corresponding European Patent Application No. 23171746.3, dated Sep. 29, 2023, 11 pages. [cited by applicant]
Seitz et al., “Key Management for Encrypted Data Storage in Distributed Systems”, Second IEEE International Security in Storage Workshop, Oct. 31, 2003, 11 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enablers for Network Automation (eNA) for the 5G system (5GS) Phase 2; (Release 17)”, 3GPP TR … [cited by applicant]
“Update on the Solution #5: Providing the Security protection of data via Messaging Framework”, 3GPP TSG-SA3 Meeting #104-e, S3-213154, Agenda: 5.16, Ericsson, Aug. 16-27, 2021, 4 pages. [cited by applicant]
Cited By (1)
US 12,699,700