IP Library Granted Patent US 12,010,146
Granted Patent B2
US 12,010,146 · App. 17/419,180 · Granted Jun 11, 2024

Method, system and apparatus for unified security configuration management

Inventors: Wei Zheng (Hangzhou, CN); Cheng Cai (Hangzhou, CN); Yulong Zhang (Hangzhou, CN); Xiaoguang Zhao (Hangzhou, CN); Silke Holtmanns (Klaukkala, FI); Ian Justin Oliver (Soderkulla, FI)
Assignee: Nokia Solutions and Networks Oy
H04L63/20G06F9/45558H04L9/3263H04L63/0272H04L63/205G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,010,146
App. No.
17/419,180
Granted
Jun 11, 2024
Kind
B2
Abstract

Methods and apparatus are disclosed for unified security configuration management. A method may comprise: determine a security configuration to be executed; determine at least one security application which is installed on at least one node and is associated with the security configuration; format for the security configuration, instructions corresponding to each of the at least one security application, respectively; and send the instructions to the at least one node for respective configuration for each of the at least one security application.

Claims (45)

1. A method, comprising:

determining in a server a security configuration to be executed;

determining at least two different security applications which are installed on at least one node and are associated with the security configuration, wherein the at least two different security applications use different security protocols;

according to a security protocol used by each of the at least two different security applications, formatting for the security configuration, instructions corresponding to each of the at least two different security application, respectively; and

sending the instructions to the at least one node for respective configuration for each of the at least two different security applications, wherein determining at least two different security applications comprises obtaining address information of the at least one node on which the at least two different security applications are installed, and wherein the address information is obtained from a virtual network function management entity.

2. The method according to claim 1 , wherein the determining of the security configuration is triggered by the server.

3. The method according to claim 1 , wherein the determining of the security configuration is triggered in response to a request from one of the at least one node.

4. The method according to claim 1 , further comprising,

receiving a request for executing the security configuration; and

checking whether the security configuration is supported.

5. The method according to claim 1 , wherein the at least one node comprises different network slices, or different virtual network functions and virtual machines.

6. The method according to claim 1 , wherein the security configuration relates to at least one of the following: algorithms, keys, parameter for algorithms, seeds, algorithm implementations, security libraries and versions of a security protocol.

7. The method according to claim 1 , further comprising:

before the sending, signing the instructions with a cryptographic key bound to a certificate of the server.

8. The method according to claim 7 , further comprising:

signing a state of the server; and

sending the signed state to the at least one node.

9. The method according to claim 1 , further comprises:

predefining scripts for construction instructions according to a given security protocol;

storing the predefined scripts; and

retrieving the scripts when it is determined that the instructions to be formatted correspond to a security application using the given security protocol.

10. An apparatus, comprising:

at least one processor;

at least one memory including computer program code, the memory and the computer program code configured to, working with the at least one processor, cause the apparatus to:

determine a security configuration to be executed;

determine at least two different security applications which is installed on at least one node and are associated with the security configuration, wherein the at least two different security applications use different security protocols;

according to a security protocol used by each of the at least two different security applications, format for the security configuration, instructions corresponding to each of the at least one security application, respectively; and

send the instructions to the at least one node for respective configuration for each of the at least two different security applications, wherein information of the security applications comprises address information of the at least one node, and wherein the memory and the computer program code are further configured to, working with the at least one processor, to cause the apparatus to obtain the information from a virtual network function management entity.

11. The apparatus according to claim 10 , wherein the memory and the computer program code are further configured to, working with the at least one processor, to cause the apparatus to receive a request from one of the at least one node, to trigger the formatting of the instructions and the sending of the formatted instructions.

12. The apparatus according to claim 10 , wherein the security configuration relates to at least one of the following: algorithms, keys, parameter for algorithms, seeds, algorithm implementations, security libraries and versions of a security protocol.

13. The apparatus according to claim 10 , wherein the memory and the computer program code are further configured to, working with the at least one processor, to cause the apparatus to sign the instructions with a cryptographic key bound to a certificate of the apparatus.

14. The apparatus according to claim 13 , wherein the memory and the computer program code are further configured to, working with the at least one processor, to cause the apparatus to sign a state of the apparatus, and the configuration engine is further configured to send the signed state to the nodes on which the at least one security application is installed.

15. The apparatus according to claim 10 , wherein the memory and the computer program code are further configured, working with the at least one processor, to

predefine scripts for constructing instructions according to a given security protocol,

store the predefined scripts; and

retrieve the scripts when it is determined that the instructions to be formatted correspond to a security application using the given security protocol.

16. A non-transitory computer program product comprising instructions which when executed by at least one processor, cause the at least one processor to perform the following:

determining a security configuration to be executed;

determining at least two different security applications which are installed on at least one node and are associated with the security configuration, wherein the at least two different security applications use different security protocols;

according to a security protocol used by each of the at least two different security applications, formatting for the security configuration, instructions corresponding to each of the at least two different security applications, respectively; and

sending the instructions to the at least one node for respective configuration for each of the at least two different security applications, wherein determining at least two different security applications comprises obtaining address information of the at least one node on which the at least two different security applications are installed, and wherein the address information is obtained from a virtual network function management entity.

17. The non-transitory computer program product according to claim 16 , wherein the instructions cause the at least one processor to further perform the following:

predefining scripts for constructing instructions according to a given security protocol;

storing the predefined scripts; and

retrieving the scripts when it is determined that the instructions to be formatted correspond to a security application using the given security protocol.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2024
From: NOKIA SHANGHAI BELL CO., LTD.; NOKIA SOLUTIONS AND NETWORKS OY
To: NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 067175/0626 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2021
From: ZHENG, WEI; CAI, CHENG; ZHANG, YULONG; ZHAO, XIAOGUANG; HOLTMANNS, SILKE; OLIVER, IAN JUSTIN
To: NOKIA SHANGHAI BELL CO., LTD.; NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 056692/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2021
From: NOKIA SHANGHAI BELL CO., LTD.
To: NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 056700/0627 →
Continuity (1)
Related Publication 20220103599A1 · Mar 31, 2022