System and method for establishing dynamic trust credentials for network functions

    公开(公告)号:US11522721B2

    公开(公告)日:2022-12-06

    申请号:US16842060

    申请日:2020-04-07

    Abstract: Systems and methods leverage trust anchors to generate tokens which can then be used by network functions (NFs). A virtualization infrastructure manager (VIM) for a virtualized platform receives a NF software package and a certificate request token (CRT) from a management function. The NF is a virtual NF, a containerized NF, or another virtual entity (xNF) to be deployed. The CRT is digitally signed by the management function and includes a network address of a trust anchor platform and a NF profile. The VIM deploys the NF and provides the CRT to the NF. The NF obtains from the CRT the network address of the trust anchor platform, generates a certificate signing request (CSR) for a digital certificate, and submits the CSR and the CRT to the trust anchor platform. The NF receives a digital certificate from the trust anchor platform based on validation of both the CSR and CRT.

    Sidecar proxy as a service
    23.
    发明授权

    公开(公告)号:US12255875B2

    公开(公告)日:2025-03-18

    申请号:US17400173

    申请日:2021-08-12

    Abstract: Disclosed are embodiments for injecting sidecar proxy capabilities into non-sidecar applications, allowing such non-sidecar applications to communicate with a service mesh architecture. In an embodiment, a method comprises receiving a request to instantiate a proxy for a non-sidecar application at a service mesh gateway (SMG). The SMG then instantiates the proxy in response to the request and broadcasts network information of the non-sidecar application to a mesh controller deployed in a containerized environment. Finally, the SMG (via the proxy) transmits data over a control plane that is communicatively coupled to the mesh controller.

    SYSTEMS AND METHODS FOR SECURE ROAMING NETWORK STEERING

    公开(公告)号:US20250016854A1

    公开(公告)日:2025-01-09

    申请号:US18347021

    申请日:2023-07-05

    Abstract: A system described herein may request, from a first network, access parameters associated with a User Equipment (“UE”) and a second network. The first network may be, for example, a home network with respect to the UE and the second network may be a roaming network with respect to the UE. The system may receive, from the first network, the requested access parameters associated with the UE and the second network, which may include authentication information associated with the first network (e.g., as provided by an authentication system of the first network). The system may output the access parameters and the authentication information to the UE, which may verify the access parameters based on the authentication information, select one or more access parameters of the verified access parameters, and request a communication session establishment with the second network in accordance with the selected one or more access parameters.

    Systems and methods for null-scheme access authorization

    公开(公告)号:US11910480B2

    公开(公告)日:2024-02-20

    申请号:US17233030

    申请日:2021-04-16

    CPC classification number: H04W8/20 H04W8/12 H04W12/06 H04W60/04

    Abstract: A method may include receiving, at a network device, a registration request that comprises a subscription concealed identifier (SUCI) associated with a particular user equipment (UE) device. The network device determines whether the SUCI indicates a request for null-scheme network access; and retrieves a scheme authorization parameter for the UE device when it is determined that the SUCI indicates a request for null-scheme network access. The scheme authorization parameter indicates whether the UE device is authorized for null-scheme access to a service provider network. The network device determines whether the UE device is authorized for null-scheme network access based on the retrieved scheme authorization parameter and performs processing associated with null-scheme network access when it is determined that the particular UE device is authorized for null-scheme network access.

    SYSTEMS AND METHODS FOR SECURING NETWORK FUNCTION SUBSCRIBE NOTIFICATION PROCESS

    公开(公告)号:US20220353263A1

    公开(公告)日:2022-11-03

    申请号:US17242419

    申请日:2021-04-28

    Abstract: A network device receives, from a requester, an access token request associated with subscribing a consumer network function (NF) to a resource provided by a producer NF, where the access token request includes a notification identifier identifying where the consumer NF is to receive content and/or notifications, associated with the resource, from the producer NF. The network device validates the requester and generates an access token and an access token response based on successfully validating the requester. The network device signs the notification identifier as a component of the access token response and sends the access token response, with the signed notification identifier, to the requester for use in requesting a subscription to the resource for the consumer NF from the producer NF.

    SYSTEMS AND METHODS FOR NULL-SCHEME ACCESS AUTHORIZATION

    公开(公告)号:US20220337994A1

    公开(公告)日:2022-10-20

    申请号:US17233030

    申请日:2021-04-16

    Abstract: A method may include receiving, at a network device, a registration request that comprises a subscription concealed identifier (SUCI) associated with a particular user equipment (UE) device. The network device determines whether the SUCI indicates a request for null-scheme network access; and retrieves a scheme authorization parameter for the UE device when it is determined that the SUCI indicates a request for null-scheme network access. The scheme authorization parameter indicates whether the UE device is authorized for null-scheme access to a service provider network. The network device determines whether the UE device is authorized for null-scheme network access based on the retrieved scheme authorization parameter and performs processing associated with null-scheme network access when it is determined that the particular UE device is authorized for null-scheme network access.

    Systems and methods for using a unique routing indicator to connect to a network

    公开(公告)号:US11432158B2

    公开(公告)日:2022-08-30

    申请号:US16988988

    申请日:2020-08-10

    Abstract: In some implementations, a device of a network may receive, from a user equipment (UE), a request associated with enabling the UE to access a network, wherein the request includes a first routing indicator. The device may identify an authentication manager, of the network, that is mapped to the first routing indicator in an entry of a routing table of the network. The device may route the request to the authentication manager of the network to permit the authentication manager to authenticate the UE. The device may purge, based on the request being routed to the authentication manager, the entry to remove the first routing indicator from the routing table. The device may store, after purging the entry, a second routing indicator in the entry to map the second routing indicator to the authentication manager, wherein the second routing indicator is different from the first routing indicator.

Patent Agency Ranking