IP Library › Granted Patent US 11,968,315
Granted Patent B2
US 11,968,315 · App. 18/053,899 · Granted Apr 23, 2024

System and method for establishing dynamic trust credentials for network functions

Inventors: Vinod Kumar Choyi (Conshohocken, PA); Sudhakar Reddy Patil (Flower Mound, TX); Jayesh Kumar Laad (Ashland, MA)
Assignee: Verizon Patent and Licensing Inc.
H04L9/3268G06F9/455G06F21/44H04L9/006H04L9/3236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,968,315
App. No.
18/053,899
Granted
Apr 23, 2024
Kind
B2
Abstract

Systems and methods leverage trust anchors to generate tokens which can then be used by network functions (NFs). A virtualization infrastructure manager (VIM) for a virtualized platform receives a NF software package and a certificate request token (CRT) from a management function. The NF is a virtual NF, a containerized NF, or another virtual entity (xNF) to be deployed. The CRT is digitally signed by the management function and includes a network address of a trust anchor platform and a NF profile. The VIM deploys the NF and provides the CRT to the NF. The NF obtains from the CRT the network address of the trust anchor platform, generates a certificate signing request (CSR) for a digital certificate, and submits the CSR and the CRT to the trust anchor platform. The NF receives a digital certificate from the trust anchor platform based on validation of both the CSR and CRT.

Claims (59)

1. A method, comprising:

receiving, by a network function and from a virtualization infrastructure manager (VIM), a certificate request token (CRT) for the network function, wherein the CRT is digitally signed by a management function and includes:

a network address of a trust anchor platform for the network function, and

a Certificate Attribute List (CAL) with customization parameters for the network function;

submitting, by the network function and to the trust anchor platform, a certificate signing request (CSR) and the CRT, wherein the CAL customization parameters supersede parameters in the CSR; and

receiving, by the network function and based on validation of the CSR and CRT, a digital certificate from the trust anchor platform, wherein the digital certificate includes limitations consistent with the CAL customization parameters.

2. The method of claim 1 , further comprising:

obtaining, by the network function and from the CRT, the network address of the trust anchor platform; and

generating, by the network function, the CSR to request the digital certificate.

3. The method of claim 1 , wherein the network function is one of a virtual network function, a containerized network function, or another virtual entity to be deployed on a virtualized platform associated with the VIM.

4. The method of claim 1 , further comprising:

obtaining, by the management function, a software package for the network function;

verifying, by the management function, authenticity of the software package;

generating, by the management function, the CRT; and

sending, by the management function and to the VIM, the software package and the CRT.

5. The method of claim 1 , further comprising:

binding, by the network function and prior to the submitting, the CRT to the CSR.

6. The method of claim 1 , wherein the CRT further includes a profile for the network function and custom information particular to rights granted to the network function.

7. The method of claim 6 , wherein the custom information includes one or more of:

a type of request,

a signature algorithm type,

life-cycle management parameters, and

a hash value based on the profile.

8. The method of claim 1 , wherein the CAL customization parameters include a validity time period for the digital certificate.

9. The method of claim 1 , further comprising:

validating the CRT by the trust anchor platform; and

generating the digital certificate by the trust anchor platform after validating the CRT.

10. A system, comprising:

a first network device configured to execute a network function to:

receive, from a virtualization infrastructure manager (VIM), a certificate request token (CRT) for the network function, wherein the CRT is digitally signed by a management function and includes: a network address of a trust anchor platform for the network function, and a Certificate Attribute List (CAL) with customization parameters for the network function;

submit, to the trust anchor platform, a certificate signing request (CSR) and the CRT, wherein the CAL customization parameters supersede parameters in the CSR; and

receive, based on validation of the CSR and CRT, a digital certificate from the trust anchor platform, wherein the digital certificate includes limitations consistent with the CAL customization parameters.

11. The system of claim 10 , wherein the first network device is further configured to:

obtain, from the CRT, the network address of the trust anchor platform; and

generate the CSR to request the digital certificate for the network function.

12. The system of claim 10 , wherein the network function is one of a virtual network function, a containerized network function, or another virtual entity to be deployed on a virtualized platform associated with the VIM.

13. The system of claim 10 , further comprising:

a second network device configured to:

obtain a software package for the network function;

verify authenticity of the software package;

generate the CRT; and

send, to the VIM, the software package and the CRT.

14. The system of claim 10 , wherein the first network device is further configured to:

bind the CRT to the CSR prior to submitting the CSR.

15. The system of claim 10 , wherein the CAL customization parameters include a validity time period for the digital certificate.

16. The system of claim 10 , further comprising:

the trust anchor platform configured to:

validate the both the CSR and the CRT; and

generate the digital certificate after successfully validating the CSR and the CRT.

17. The system of claim 16 , wherein the trust anchor platform includes a public key infrastructure system.

18. A non-transitory computer-readable medium containing instructions executable by at least one processor, the non-transitory computer-readable medium comprising one or more instructions for a network function to:

receive, from a virtualization infrastructure manager (VIM), a certificate request token (CRT) for the network function, wherein the CRT is digitally signed by a management function and includes: a network address of a trust anchor platform for the network function, and a Certificate Attribute List (CAL) with customization parameters for the network function;

submit, to the trust anchor platform, a certificate signing request (CSR) and the CRT, wherein the CAL customization parameters supersede parameters in the CSR; and

receive, based on validation of the CSR and CRT, a digital certificate from the trust anchor platform, wherein the digital certificate includes limitations consistent with the CAL customization parameters.

19. The non-transitory computer-readable medium of claim 18 , wherein the one or more instructions for submitting the CSR and the CRT comprise instructions for:

binding the CRT to the CSR.

20. The non-transitory computer-readable medium of claim 18 , wherein the CRT further includes a profile for the network function and custom information particular to rights granted to the network function, the custom information including one or more of:

life-cycle management parameters, and

a hash value based on the profile.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THIRD INVENTOR'S LAST NAME PREVIOUSLY RECORDED AT REEL: 061707 FRAME: 0934. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Dec 2, 2022
From: CHOYI, VINOD KUMAR; PATIL, SUDHAKAR REDDY; LAAD, JAYESH KUMAR
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 062043/0591 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2022
From: CHOYI, VINOD KUMAR; PATIL, SUDHAKAR REDDY; LAND, JAYESH KUMAR
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 061707/0934 →
Continuity (2)
Continuation 16842060 · Apr 7, 2020
Related Publication 20230064698A1 · Mar 2, 2023