IP Library › Granted Patent US 12,418,528
Granted Patent B2
US 12,418,528 · App. 18/020,549 · Granted Sep 16, 2025

Establishment of secure communication

Inventors: Kazi Wali Ullah (Espoo, FI); Ari Pietikäinen (Espoo, FI)
Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
H04L63/0876H04L63/0428H04L63/102H04L63/108H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,528
App. No.
18/020,549
Granted
Sep 16, 2025
Kind
B2
Abstract

Methods and apparatus for establishing enhanced secure communication between two Network Entities. A method performed by a first Network Entity (NE 1 ) to establish communication between the NE 1 and a second Network Entity (NE 2 ), wherein both NE 1 and NE 2 trust a Trusted Network Entity (TNE). The method comprises establishing an initial connection with the NE 2 , obtaining a report associated with NE 1 from TNE, wherein the report is signed by the TNE and providing the report associated with NE 1 to NE 2.

Claims (38)

1. A method performed by a first Network Entity (NE 1 ) to establish communication between the NE 1 and a second Network Entity (NE 2 ), wherein both NE 1 and NE 2 trust a Trusted Network Entity (TNE), the method comprising:

establishing an initial connection between NE 1 and NE 2 ;

obtaining a report associated with NE 1 from TNE, the report being signed by the TNE, the report comprising an identity of NE 1 , a signature, and trust evaluation information (TEI) associated with NE 1 , the signature comprising a timestamp; and

providing the report associated with NE 1 to NE 2 .

2. The method according to claim 1 , wherein the report associated with NE 1 comprise a set of TEI associated with NE 1 that helps to establish the trust relationship between NE 1 and NE 2 , or wherein the report associated with NE 1 comprise a set of TEI associated with NE 1 that helps NE 2 to evaluate whether it is trustworthy to continue communication with NE 1 .

3. The method according to claim 1 , wherein the TEI associated with NE 1 comprises at least one of:

secure boot information of NE 1 ,

measured boot information of NE 1 ,

remote attestation information of NE 1 ,

Highest Common Vulnerabilities and Exposer (CVE) score of NE 1 ,

trust index of NE 1 , and a risk index of NE 1 .

4. The method according to claim 1 , further comprising receiving from NE 2 a message of whether to continue communication with NE 1 .

5. The method according to claim 1 , further comprising sending to NE 2 or TNE a request for providing a report associated with NE 2 , wherein the report is signed by the TNE.

6. A method performed by a second Network Entity (NE 2 ) to establish communication between a first Network Entity (NE 1 ) and the NE 2 , wherein both NE 1 and NE 2 trust a Trusted Network Entity (TNE), the method comprising:

establishing an initial connection between NE 2 and NE 1 ;

obtaining a report associated with NE 1 , the report being signed by TNE, the report comprising an identity of NE 1 , a signature, and trust evaluation information (TEI) associated with NE 1 , the signature comprising a timestamp; and

verifying the report associated with NE 1 .

7. The method according to claim 6 , wherein the report associated with NE 1 comprise a set of TEI associated with NE 1 that helps to establish the trust relationship between NE 1 and NE 2 , or wherein the report associated with NE 1 comprise a set of TEI associated with NE 1 that helps NE 2 to evaluate whether it is trustworthy to continue communication with NE 1 .

8. The method according to claim 6 , wherein the TEI associated with NE 1 comprises at least one of:

secure boot information of NE 1 ,

measured boot information of NE 1 ,

remote attestation information of NE 1 ,

Highest Common Vulnerabilities and Exposer (CVE) score of NE 1 ,

a trust index of NE 1 , and

risk index of NE 1 .

9. The method according to claim 6 , further comprising sending a message of whether to continue communication with NE 1 to NE 1 .

10. A method performed by a Trusted Network Entity (TNE), the method comprising:

obtaining a set of trust evaluation information of a Network Entity (NE); and

generating a report associated with the NE, the report being signed by the TNE, the report comprising an identity of the NE, a signature, and trust evaluation information (TEI) associated with the NE, the signature comprising a timestamp.

11. The method according to claim 10 , wherein the report associated with the NE comprises a set of trust evaluation information associated with the NE that helps to establish the trust relationship between the NE and another NE, or wherein the report associated with the NE comprises a set of trust evaluation information associated with the NE that helps another NE to evaluate whether it is trustworthy to continue communication with the NE.

12. The method according to claim 10 , wherein the TEI associated with the NE comprises at least one of:

secure boot information of the NE,

measured boot information of the NE,

remote attestation information of the NE,

Highest Common Vulnerabilities and Exposer (CVE) score of the NE,

a trust index of the NE, and

a risk index of the NE.

13. The method according to claim 10 , further comprising providing the report associated with the NE to the NE or to another NE.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2023
From: ULLAH, KAZI WALI; PIETIKÄINEN, ARI
To: OY L M ERICSSON AB
Reel/Frame 062644/0362 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2023
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 062644/0387 →
Continuity (1)
Related Publication 20230308440A1 · Sep 28, 2023
References Cited (24)
US 9876823B2 · Smith · 2018 [cited by examiner]
US 9989043B2 · Lee · 2018 [cited by examiner]
US 10299128B1 · Suthar · 2019 [cited by examiner]
US 10939308B2 · Suthar · 2021 [cited by examiner]
US 11206715B2 · Pocha · 2021 [cited by examiner]
US 11356453B1 · Victor · 2022 [cited by examiner]
US 11381584B1 · Victor · 2022 [cited by examiner]
US 20050138384A1 · Brickell · 2005 [cited by examiner]
US 20150113618A1 · Sinha et al. · 2015 [cited by applicant]
US 20170078922A1 · Raleigh · 2017 [cited by examiner]
US 20190065406A1 · Steiner · 2019 [cited by examiner]
US 20190068608A1 · Boland · 2019 [cited by examiner]
US 20190311123A1 · Lal · 2019 [cited by examiner]
US 20200045519A1 · Raleigh · 2020 [cited by examiner]
US 20200128022A1 · Bleikertz · 2020 [cited by examiner]
US 20200145419A1 · Yitbarek · 2020 [cited by examiner]
US 20200167476A1 · Boulton · 2020 [cited by examiner]
US 20200311281A1 · Boulton · 2020 [cited by examiner]
US 20210081545A1 · Mulligan · 2021 [cited by examiner]
US 20210334797A1 · Tripathy · 2021 [cited by examiner]
US 20220014512A1 · Raleigh · 2022 [cited by examiner]
US 20220286474A1 · Kuppa · 2022 [cited by examiner]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2 (Release 15)”, 3GPP TS 23.501 V15.2.0, Jun. 2018, 217 pages. [cited by applicant]
Knauth, Thomas, et al., “Integrating Intel SGX Remote Attestation with Transport Layer Security”, arXiv:1801.05863, Computer Science > Cryptography and Security, Version 1.0, Jan. 17, 2018, 1-11. [cited by applicant]