IP Library Granted Patent US 11,340,933
Granted Patent B2
US 11,340,933 · App. 16/940,851 · Granted May 24, 2022

Method and apparatus for secrets injection into containers for 5G network elements

Inventors: James Donald Reno (Scotts Valley, CA); Michael Brown (Fremont, CA); Akshay Rajesh Baheti (Redwood City, CA); Michael Cameron (McKinney, TX)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
G06F9/45558G06F9/455G06F9/45504G06F9/45533G06F21/00G06F21/12G06F21/121G06F21/30G06F21/445H04W8/08H04W12/122H04W48/16H04W80/10G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,340,933
App. No.
16/940,851
Granted
May 24, 2022
Kind
B2
Abstract

A method and system for managing dynamic runtime information provision for a container implementing a Session Management Function (SMF) executed by an electronic device in a 3 rd generation partnership project (3GPP) 5 th Generation (5G) mobile network core. The method includes starting a container image load, the container image including at least a secret sub unit and an application sub unit, the application sub unit providing the SMF, determining an input source to provide a secret value for the container, the input source identified by information in the secret sub unit in the container image, and providing the secret value to a destination sub unit of the container.

Claims (36)

1. A method of managing dynamic runtime information provision for a container implementing a Session Management Function (SMF) executed by an electronic device in a 3 rd generation partnership project (3GPP) 5 th Generation (5G) mobile network core, the method comprising:

starting a container image load, the container image including at least a secret sub unit and an application sub unit, the application sub unit providing the SMF;

determining an input source to provide a secret value for the container, the input source identified by information in the secret sub unit in the container image; and

providing the secret value to a destination sub unit of the container.

2. The method of claim 1 , further comprising:

determining the destination sub unit of the container to receive the secret value is the SMF, the destination sub unit identified by information in the secret sub unit in the container image.

3. The method of claim 1 , wherein the secret value is unique to the container within the 5G mobile network core.

4. The method of claim 1 , wherein the secret source includes an algorithm defined by the secret sub unit.

5. The method of claim 1 , further comprising:

generating a query to an administrator interface to retrieve data to be utilized to derive the secret value.

6. A method of managing dynamic runtime information provision for a container implementing an Access and Mobility Management Function (AMF) executed by an electronic device in a 3 rd generation partnership project (3GPP) 5 th Generation (5G) mobile network core, the method comprising:

starting a container image load, the container image including at least a secret sub unit and an application sub unit, the application sub unit providing the AMF;

determining an input source to provide a secret value for the container, the input source identified by information in the secret sub unit in the container image; and

providing the secret value to a destination sub unit of the container.

7. The method of claim 6 , further comprising:

determining the destination sub unit of the container to receive the secret value is the AMF, the destination sub unit identified by information in the secret sub unit in the container image.

8. The method of claim 6 , wherein the secret value is unique to the container.

9. The method of claim 6 , wherein the secret source includes an algorithm defined by the secret sub unit.

10. The method of claim 6 , further comprising:

generating a query to an administrator interface to retrieve data to be utilized to derive the secret value.

11. An electronic device in a 3 rd generation partnership project (3GPP) 5 th Generation (5G) mobile network core, the electronic device configured to implement a container management system, the container management system to support managing dynamic runtime information provision for a container implementing a Session Management Function (SMF), the electronic device comprising:

a non-transitory computer-readable medium having stored therein a container manager; and

a processor coupled to the non-transitory computer-readable medium, the processor to execute the container manager, the container manager to start a container image load, the container image including at least a secret sub unit and an application sub unit, the application sub unit providing the SMF, to determine an input source to provide a secret value for the container, the input source identified by information in the secret sub unit in the container image, and to provide the secret value to a destination sub unit of the container.

12. The electronic device of claim 11 , further comprising:

a secret store coupled to the processor to store information for determining the secret value.

13. The electronic device of claim 11 , wherein the container manager includes a runtime secret processing component to generate a query to an administrator interface to retrieve data to be utilized to derive the secret value.

14. The electronic device of claim 11 , wherein the container manager is further to determine the destination sub unit of the container to receive the secret value is the SMF, the destination sub unit identified by information in the secret sub unit in the container image.

15. The electronic device of claim 11 , wherein the secret value is unique to the container within the 5G mobile network core.

16. An electronic device in a 3 rd generation partnership project (3GPP) 5 th Generation (5G) mobile network core, the electronic device configured to implement a container management system, the container management system to support managing dynamic runtime information provision for a container implementing an Access and Mobility Management Function (AMF), the electronic device comprising:

a non-transitory computer-readable medium having stored therein a container manager; and

a processor coupled to the non-transitory computer-readable medium, the processor to execute the container manager, the container manager to start a container image load, the container image including at least a secret sub unit and an application sub unit, the application sub unit providing the AMF, to determine an input source to provide a secret value for the container, the input source identified by information in the secret sub unit in the container image, and to provide the secret value to a destination sub unit of the container.

17. The electronic device of claim 16 , further comprising:

a secret store coupled to the processor to store information for determining the secret value.

18. The electronic device of claim 16 , wherein the container manager includes a runtime secret processing component to generate a query to an administrator interface to retrieve data to be utilized to derive the secret value.

19. The electronic device of claim 16 , wherein the container manager is further to determine the destination sub unit of the container to receive the secret value is the AMF, the destination sub unit identified by information in the secret sub unit in the container image.

20. The electronic device of claim 16 , wherein the secret value is unique to the container within the 5G mobile network core.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2020
From: RENO, JAMES DONALD; BROWN, MICHAEL; BAHETI, AKSHAY RAJESH; CAMERON, MICHAEL
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 053873/0814 →
Continuity (2)
Continuation In Part 15813016 · Nov 14, 2017
Related Publication 20200359451A1 · Nov 12, 2020