IP Library › Granted Patent US 12,568,369
Granted Patent B2
US 12,568,369 · App. 18/688,535 · Granted Mar 3, 2026

Internet Protocol (IP) assignment and secure traffic for network elements deployed over untrusted transport network

Inventors: Deepak Shivanagouda Patil (Karnataka, IN); Basawaraj Eshwaraj Nadagatti (Karnataka, IN); Satish Singh (Karnataka, IN); Ravi Ramesh Bhat (Karnataka, IN)
Assignee: RAKUTEN SYMPHONY, INC.
H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,369
App. No.
18/688,535
Granted
Mar 3, 2026
Kind
B2
Abstract

Embodiments of present disclosure disclose internet protocol (IP) assignment and secure traffic for network elements deployed over untrusted transport network. In an embodiment, base station ( 101 ) transmits an Open Cloud (O-cloud) available registration request to an operator network system ( 103 ) through First Secure Tunnel (FST) ( 133 ) established between operator network system ( 103 ) and base station ( 101 ). The FST is terminated upon receiving network information related to each of plurality of O-cloud entities of O-cloud through FST from operator network system. Thereafter, base station ( 101 ) transmits second authentication request to operator network system for establishing Second Secure Tunnel (SST) ( 135 ) between operator network system and base station. Finally, base station establishes SST between operator network system and base station when network information is authenticated. The established SST allows bi-directional traffic related to each of plurality of O-cloud entities. The present disclosure helps in handling the traffic at the operator network system.

Claims (29)

1 . A base station ( 101 ), comprising:

a memory storing instructions; and

a processor configured to execute the instructions to:

transmit an Open Cloud (O-cloud) available registration request to an operator network system ( 105 ) through a first secure tunnel ( 133 ) established between the operator network system ( 105 ) and the base station ( 101 ), wherein the registration request comprises an O-cloud Identification (ID) of an O-cloud associated with base station ( 101 ) of a cell site;

terminate the first secure tunnel ( 133 ) upon receiving a network information related to each of a plurality of O-cloud entities of the O-cloud through the first secure tunnel ( 133 ) from the operator network system ( 105 ) in response to the registration request;

transmit a second authentication request to the operator network system ( 105 ) for establishing a second secure tunnel ( 135 ) between the operator network system ( 105 ) and the base station ( 101 ), wherein the second authentication request comprises the network information related to each of the plurality of O-cloud entities and a base station ( 101 ) operator signed certificate to be authenticated; and

establish the second secure tunnel ( 135 ) between the operator network system ( 105 ) and the base station ( 101 ) when the network information related to each of the plurality of O-cloud entities is authenticated, wherein the established second secure tunnel ( 135 ) allows bi-directional traffic related to each of the plurality of O-cloud entities.

2 . The base station ( 101 ) as claimed in claim 1 , wherein prior to transmitting the registration request, the processor is configured to:

transmit a first authentication request to the operator network system ( 105 ), for obtaining an inner IP of the base station ( 101 ) and establishing the first secure tunnel ( 133 ) between the operator network system ( 105 ) and the base station ( 101 ), wherein the first authentication request comprises a predefined certificate related to the cell site to be authenticated; and

establish the first secure tunnel ( 133 ) when the predefined certificate received in the first authentication request is determined to be valid, wherein a first authentication response comprising an inner IP of the base station ( 101 ) is received from the operator network system ( 105 ).

3 . The base station ( 101 ) as claimed in claim 1 , wherein the network information comprises at least one of an inner IP, traffic selectors, an IP mapping related to the O-cloud and an internal Domain Name System (DNS), detected by the operator network system ( 105 ) based on the O-cloud ID.

4 . A method, comprising:

transmitting, by a base station ( 101 ), an Open Cloud (O-cloud) available registration request to an operator network system ( 105 ) through a first secure tunnel ( 133 ) established between the operator network system ( 105 ) and the base station ( 101 ), wherein the registration request comprises an O-cloud Identification (ID) of an O-cloud associated with base station ( 101 ) of a cell site;

terminating, by the base station ( 101 ), the first secure tunnel ( 133 ) upon receiving a network information related to each of a plurality of O-cloud entities of the O-cloud through the first secure tunnel ( 133 ) from the operator network system ( 105 ) in response to the registration request;

transmitting, by the base station ( 101 ), a second authentication request to the operator network system ( 105 ) for establishing a second secure tunnel ( 135 ) between the operator network system ( 105 ) and the base station ( 101 ), wherein the second authentication request comprises the network information related to each of the plurality of O-cloud entities and a base station ( 101 ) operator signed certificate to be authenticated; and

establishing, by the base station ( 101 ), the second secure tunnel ( 135 ) between the operator network system ( 105 ) and the base station ( 101 ) when the network information related to each of the plurality of O-cloud entities is authenticated, wherein the established second secure tunnel ( 135 ) allows bi-directional traffic related to each of the plurality of O-cloud entities.

5 . The method as claimed in claim 4 , wherein prior to transmitting the registration request the method comprises:

transmitting, by the base station ( 101 ), a first authentication request to the operator network system ( 105 ), for obtaining an inner IP of the base station ( 101 ) and establishing the first secure tunnel ( 133 ) between the operator network system ( 105 ) and the base station ( 101 ), wherein the first authentication request comprises a predefined certificate related to the cell site to be authenticated; and

establishing, by the base station ( 101 ), the first secure tunnel ( 133 ) when the predefined certificate received in the first authentication request is determined to be valid, wherein a first authentication response comprising an inner IP of the base station ( 101 ) is received from the operator network system ( 105 ).

6 . The method as claimed in claim 4 , wherein the network information comprises at least one of an inner IP, traffic selectors, an IP mapping related to the O-cloud and an internal Domain Name System (DNS), detected by the operator network system ( 105 ) based on the O-cloud ID.

7 . A non-transitory computer readable medium including instructions stored thereon that when processed by at least one processor, cause a base station ( 101 ) to perform operations comprising:

transmitting, by a base station ( 101 ), an Open Cloud (O-cloud) available registration request to an operator network system ( 105 ) through a first secure tunnel ( 133 ) established between the operator network system ( 105 ) and the base station ( 101 ), wherein the registration request comprises an O-cloud Identification (ID) of an O-cloud associated with base station ( 101 ) of a cell site;

terminating, by the base station ( 101 ), the first secure tunnel ( 133 ) upon receiving a network information related to each of a plurality of O-cloud entities of the O-cloud through the first secure tunnel ( 133 ) from the operator network system ( 105 ) in response to the registration request;

transmitting, by the base station ( 101 ), a second authentication request to the operator network system ( 105 ) for establishing a second secure tunnel ( 135 ) between the operator network system ( 105 ) and the base station ( 101 ), wherein the second authentication request comprises the network information related to each of the plurality of O-cloud entities and a base station ( 101 ) operator signed certificate to be authenticated; and

establishing, by the base station ( 101 ), the second secure tunnel ( 135 ) between the operator network system ( 105 ) and the base station ( 101 ) when the network information related to each of the plurality of O-cloud entities is authenticated, wherein the established second secure tunnel ( 135 ) allows bi-directional traffic related to each of the plurality of O-cloud entities.

8 . The medium as claimed in claim 7 , wherein prior to transmitting the registration request the instructions cause the processor to:

transmit a first authentication request to the operator network system ( 105 ), for obtaining an inner IP of the base station ( 101 ) and establishing the first secure tunnel ( 133 ) between the operator network system ( 105 ) and the base station ( 101 ), wherein the first authentication request comprises a predefined certificate related to the cell site to be authenticated; and

establish the first secure tunnel ( 133 ) when the predefined certificate received in the first authentication request is determined to be valid, wherein a first authentication response comprising an inner IP of the base station ( 101 ) is received from the operator network system ( 105 ).

9 . The medium as claimed in claim 7 , wherein the network information comprises at least one of an inner IP, traffic selectors, an IP mapping related to the O-cloud and an internal Domain Name System (DNS), detected by the operator network system ( 105 ) based on O-cloud ID.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2024
From: PATIL, DEEPAK SHIVANAGOUDA; NADAGATTI, BASAWARAJ ESHWARAJ; SINGH, SATISH; BHAT, RAVI RAMESH
To: RAKUTEN SYMPHONY, INC.
Reel/Frame 066618/0311 →
Priority Claims (1)
IN 202341074270 · Oct 31, 2023 · national
Continuity (1)
Related Publication 20250247694A1 · Jul 31, 2025
References Cited (16)
US 7304974B2 · Yang · 2007 [cited by examiner]
US 11917527B2 · Chou · 2024 [cited by examiner]
US 20110252230A1 · Segre · 2011 [cited by examiner]
US 20140023040A1 · Son · 2014 [cited by examiner]
US 20170257886A1 · Adjakple · 2017 [cited by examiner]
US 20190007409A1 · Totale · 2019 [cited by examiner]
US 20210258866A1 · Chou · 2021 [cited by examiner]
US 20240104192A1 · Kalle · 2024 [cited by examiner]
US 20240154658A1 · Chandwani · 2024 [cited by examiner]
US 20240259879A1 · Ranganath · 2024 [cited by examiner]
US 20250055681A1 · Ince · 2025 [cited by examiner]
M. Polese, L. Bonati, S. D'Oro, S. Basagni and T. Melodia, “Understanding O-RAN: Architecture, Interfaces, Algorithms, Security, and Research Challenges,” in IEEE Communications Surveys & Tutorials, vol. 25, No. 2, pp. … [cited by examiner]
O-Ran Alliance, O-Ran Working Groupd 6 (Cloudification and ORchestration) Cloud Architecture and Deployment Scenarios for O-RAN Virtualized RAN, O-RAN.WG6.CADS-v08.01, Feb. 2025. (Year: 2025). [cited by examiner]
Y. Huang et al., “Validation of Current O-RAN Technologies and Insights on the Future Evolution,” in IEEE Journal on Selected Areas in Communications, vol. 42, No. 2, pp. 487-505, Feb. 2024. (Year: 2024). [cited by examiner]
Y. Cao, T. Jiang and Z. Han, “A Survey of Emerging M2M Systems: Context, Task, and Objective,” in IEEE Internet of Things Journal, vol. 3, No. 6, pp. 1246-1258, Dec. 2016. (Year: 2016). [cited by examiner]
J. Groen et al., “Securing O-RAN Open Interfaces,” in IEEE Transactions on Mobile Computing, vol. 23, No. 12, pp. 11265-11277, Dec. 2024. (Year: 2024). [cited by examiner]