Methods and systems for 5G slicing based on dynamic security properties

    公开(公告)号:US12262206B2

    公开(公告)日:2025-03-25

    申请号:US18314219

    申请日:2023-05-09

    Abstract: Systems and methods enable the provisioning of security as a service for network slices. A network device stores definitions of multiple security assurance levels for network slices based on security parameters of assets used in the network slices. The network device stores multiple network slice templates, wherein the multiple network slice templates have different security assurance levels, of the multiple security assurance levels, for a Network Service Descriptor (NSD). The network device receives a request for a network slice with a requested security assurance level, of the multiple security assurance levels, for the NSD, and deploys the network slice using one of the network slice templates that has a security assurance level that corresponds to the requested security assurance level. The network device monitors the security parameters of the assets of the network slice for changes to the security assurance level of the deployed network slice.

    SYSTEMS AND METHODS FOR DYNAMIC AUTHORIZATION OF EXTERNAL DEVICES FOR NETWORK ACCESS

    公开(公告)号:US20240224092A1

    公开(公告)日:2024-07-04

    申请号:US18149180

    申请日:2023-01-03

    CPC classification number: H04W24/08 H04W48/02

    Abstract: A system described herein may monitor information associated with a set of User Equipment (“UEs”) associated with a first network, and may receive an access request, for access to a first UE of the set of UEs, from a second UE associated with a second network. The system may obtain, based on the access request and from the second network, monitored information associated with the second UE. The system may identify monitored information associated with the first UE and a particular access policy that is associated with the first UE and the second UE. The system may identify, based on the particular access policy, the monitored information associated with the first UE, and the monitored information associated with the second UE, whether to grant or deny the access request. The system may output, in response to the access request, an indication of whether the access request is granted or denied.

    SYSTEM AND METHOD FOR ESTABLISHING DYNAMIC TRUST CREDENTIALS FOR NETWORK FUNCTIONS

    公开(公告)号:US20230064698A1

    公开(公告)日:2023-03-02

    申请号:US18053899

    申请日:2022-11-09

    Abstract: Systems and methods leverage trust anchors to generate tokens which can then be used by network functions (NFs). A virtualization infrastructure manager (VIM) for a virtualized platform receives a NF software package and a certificate request token (CRT) from a management function. The NF is a virtual NF, a containerized NF, or another virtual entity (xNF) to be deployed. The CRT is digitally signed by the management function and includes a network address of a trust anchor platform and a NF profile. The VIM deploys the NF and provides the CRT to the NF. The NF obtains from the CRT the network address of the trust anchor platform, generates a certificate signing request (CSR) for a digital certificate, and submits the CSR and the CRT to the trust anchor platform. The NF receives a digital certificate from the trust anchor platform based on validation of both the CSR and CRT.

    METHODS AND SYSTEMS FOR 5G SLICING BASED ON DYNAMIC SECURITY PROPERTIES

    公开(公告)号:US20220217540A1

    公开(公告)日:2022-07-07

    申请号:US17143589

    申请日:2021-01-07

    Abstract: Systems and methods enable the provisioning of security as a service for network slices. A network device stores definitions of multiple security assurance levels for network slices based on security parameters of assets used in the network slices. The network device stores multiple network slice templates, wherein the multiple network slice templates have different security assurance levels, of the multiple security assurance levels, for a Network Service Descriptor (NSD). The network device receives a request for a network slice with a requested security assurance level, of the multiple security assurance levels, for the NSD, and deploys the network slice using one of the network slice templates that has a security assurance level that corresponds to the requested security assurance level. The network device monitors the security parameters of the assets of the network slice for changes to the security assurance level of the deployed network slice.

    WIRELESS NETWORK POLICY MANAGER FOR A SERVICE MESH

    公开(公告)号:US20210392477A1

    公开(公告)日:2021-12-16

    申请号:US16899150

    申请日:2020-06-11

    Abstract: A computer device may include a memory storing instructions and processor configured to execute the instructions to host a network function container that implements a microservice for a network function in a wireless communications network, wherein the network function container is deployed by a container orchestration platform; host a service proxy container associated with the network function container, wherein the service proxy container is deployed by the container orchestration platform; and configure the hosted service proxy container to apply a wireless network policy to the microservice for the network function. The processor may be further configured to intercept messages associated with the microservice for the network function using the configured service proxy container; and apply the wireless network policy to the intercepted messages using the configured service proxy container.

    SYSTEM AND METHOD FOR ESTABLISHING DYNAMIC TRUST CREDENTIALS FOR NETWORK FUNCTIONS

    公开(公告)号:US20210314171A1

    公开(公告)日:2021-10-07

    申请号:US16842060

    申请日:2020-04-07

    Abstract: Systems and methods leverage trust anchors to generate tokens which can then be used by network functions (NFs). A virtualization infrastructure manager (VIM) for a virtualized platform receives a NF software package and a certificate request token (CRT) from a management function. The NF is a virtual NF, a containerized NF, or another virtual entity (xNF) to be deployed. The CRT is digitally signed by the management function and includes a network address of a trust anchor platform and a NF profile. The VIM deploys the NF and provides the CRT to the NF. The NF obtains from the CRT the network address of the trust anchor platform, generates a certificate signing request (CSR) for a digital certificate, and submits the CSR and the CRT to the trust anchor platform. The NF receives a digital certificate from the trust anchor platform based on validation of both the CSR and CRT.

Patent Agency Ranking