-
公开(公告)号:US11678193B2
公开(公告)日:2023-06-13
申请号:US17813117
申请日:2022-07-18
Applicant: Verizon Patent and Licensing Inc.
Inventor: Sudhakar Reddy Patil , Bjorn Hjelm , Kent W. Hughes , Gerardo S. Libunao , Yousif Targali
IPC: H04W12/30 , H04W12/037 , H04W12/40 , H04W12/06
CPC classification number: H04W12/35 , H04W12/037 , H04W12/06 , H04W12/40
Abstract: A device may receive, from a network device, a user equipment (UE) parameter update request notification indicating an update to a UE parameter of a universal subscriber identity module (USIM), and may generate an encrypted UE parameter update request. The device may cause the encrypted UE parameter update request to be provided to the USIM to cause the USIM to update the UE parameter and to generate an encrypted UE parameter update response. The device may receive, from the network device, the encrypted UE parameter update response, and may verify an authenticity of content of the encrypted UE parameter update response based on whether the encrypted UE parameter update response is signed by the USIM. The device may provide, to the network device, a result indicating whether the UE parameter is updated and whether the authenticity of the content of the encrypted UE parameter update response is verified.
-
公开(公告)号:US11910480B2
公开(公告)日:2024-02-20
申请号:US17233030
申请日:2021-04-16
Applicant: Verizon Patent and Licensing Inc.
Inventor: Yousif Targali , Vinod Kumar Choyi , Sudhakar Reddy Patil , Michael A. Gallagher
Abstract: A method may include receiving, at a network device, a registration request that comprises a subscription concealed identifier (SUCI) associated with a particular user equipment (UE) device. The network device determines whether the SUCI indicates a request for null-scheme network access; and retrieves a scheme authorization parameter for the UE device when it is determined that the SUCI indicates a request for null-scheme network access. The scheme authorization parameter indicates whether the UE device is authorized for null-scheme access to a service provider network. The network device determines whether the UE device is authorized for null-scheme network access based on the retrieved scheme authorization parameter and performs processing associated with null-scheme network access when it is determined that the particular UE device is authorized for null-scheme network access.
-
公开(公告)号:US20220337994A1
公开(公告)日:2022-10-20
申请号:US17233030
申请日:2021-04-16
Applicant: Verizon Patent and Licensing Inc.
Inventor: Yousif Targali , Vinod Kumar Choyi , Sudhakar Reddy Patil , Michael A. Gallagher
Abstract: A method may include receiving, at a network device, a registration request that comprises a subscription concealed identifier (SUCI) associated with a particular user equipment (UE) device. The network device determines whether the SUCI indicates a request for null-scheme network access; and retrieves a scheme authorization parameter for the UE device when it is determined that the SUCI indicates a request for null-scheme network access. The scheme authorization parameter indicates whether the UE device is authorized for null-scheme access to a service provider network. The network device determines whether the UE device is authorized for null-scheme network access based on the retrieved scheme authorization parameter and performs processing associated with null-scheme network access when it is determined that the particular UE device is authorized for null-scheme network access.
-
公开(公告)号:US20250133487A1
公开(公告)日:2025-04-24
申请号:US18489529
申请日:2023-10-18
Applicant: Verizon Patent and Licensing Inc.
Inventor: Yousif Targali , Vinod Kumar Choyi
IPC: H04W48/18 , H04W4/50 , H04W12/086 , H04W40/02 , H04W76/10
Abstract: A device may include a processor. The processor may be configured to: receive, from a User Equipment device (UE) over a wireless connection, a request to enroll an application installed on the UE to receive a service from a network slice; select a network slice to provide the service to the application on the UE; bind the application on the UE to the selected network slice; and send an enrollment reply to the UE. The processor may perform a dynamic, short-term application enrollment or a long-term application enrollment, to enable the application to access the service.
-
公开(公告)号:US12262206B2
公开(公告)日:2025-03-25
申请号:US18314219
申请日:2023-05-09
Applicant: Verizon Patent and Licensing Inc.
Inventor: Vinod Kumar Choyi , Kristen Sydney Young , Yousif Targali , Michael A. Gallagher
Abstract: Systems and methods enable the provisioning of security as a service for network slices. A network device stores definitions of multiple security assurance levels for network slices based on security parameters of assets used in the network slices. The network device stores multiple network slice templates, wherein the multiple network slice templates have different security assurance levels, of the multiple security assurance levels, for a Network Service Descriptor (NSD). The network device receives a request for a network slice with a requested security assurance level, of the multiple security assurance levels, for the NSD, and deploys the network slice using one of the network slice templates that has a security assurance level that corresponds to the requested security assurance level. The network device monitors the security parameters of the assets of the network slice for changes to the security assurance level of the deployed network slice.
-
6.
公开(公告)号:US20250088424A1
公开(公告)日:2025-03-13
申请号:US18464412
申请日:2023-09-11
Applicant: Verizon Patent and Licensing Inc.
Inventor: Yousif Targali , Shankar Venkatraman , Vishwanath Ramamurthi
IPC: H04L41/0895 , H04L41/0806 , H04W12/069
Abstract: A system described herein may maintain a set of policies associated with accessing a radio access network (“RAN”), may receive a request for a particular network function (“NF”) to access the RAN, and may determine, based on the set of policies and information included in the request, whether to grant the request to access the RAN. The system may establish, when determining that the request should be granted, connectivity between the particular NF and the RAN, where establishing the connectivity includes assigning a particular address to the particular NF, routing traffic, addressed to the particular address, to the particular NF, routing traffic, received from the particular NF, to the RAN. The system may forgo establishing connectivity between the particular NF and the RAN when determining that the request should not be granted. The RAN may include an Open RAN (“O-RAN”).
-
公开(公告)号:US11418957B2
公开(公告)日:2022-08-16
申请号:US16683775
申请日:2019-11-14
Applicant: Verizon Patent and Licensing Inc.
Inventor: Sudhakar Reddy Patil , Bjorn Hjelm , Kent W. Hughes , Gerardo S. Libunao , Yousif Targali
IPC: H04W12/30 , H04W12/40 , H04W12/06 , H04W12/037
Abstract: A device may receive, from a network device, a user equipment (UE) parameter update request notification indicating an update to a UE parameter of a universal subscriber identity module (USIM), and may generate an encrypted UE parameter update request. The device may cause the encrypted UE parameter update request to be provided to the USIM to cause the USIM to update the UE parameter and to generate an encrypted UE parameter update response. The device may receive, from the network device, the encrypted UE parameter update response, and may verify an authenticity of content of the encrypted UE parameter update response based on whether the encrypted UE parameter update response is signed by the USIM. The device may provide, to the network device, a result indicating whether the UE parameter is updated and whether the authenticity of the content of the encrypted UE parameter update response is verified.
-
公开(公告)号:US20220217540A1
公开(公告)日:2022-07-07
申请号:US17143589
申请日:2021-01-07
Applicant: Verizon Patent and Licensing Inc.
Inventor: Vinod Kumar Choyi , Kristen Sydney Young , Yousif Targali , Michael A. Gallagher
Abstract: Systems and methods enable the provisioning of security as a service for network slices. A network device stores definitions of multiple security assurance levels for network slices based on security parameters of assets used in the network slices. The network device stores multiple network slice templates, wherein the multiple network slice templates have different security assurance levels, of the multiple security assurance levels, for a Network Service Descriptor (NSD). The network device receives a request for a network slice with a requested security assurance level, of the multiple security assurance levels, for the NSD, and deploys the network slice using one of the network slice templates that has a security assurance level that corresponds to the requested security assurance level. The network device monitors the security parameters of the assets of the network slice for changes to the security assurance level of the deployed network slice.
-
公开(公告)号:US20250112908A1
公开(公告)日:2025-04-03
申请号:US18479301
申请日:2023-10-02
Applicant: Verizon Patent and Licensing Inc.
Inventor: Vinod Kumar Choyi , Yousif Targali
IPC: H04L9/40
Abstract: A method, a network device, and a non-transitory computer-readable storage medium are described in relation to an application authorization service. The application authorization service may be performed at an end device and invoked responsive to the launching of an application. The application authorization service may include validating an application certificate associated with the application, validating an attestation value, and validating a token provided by the application. The application may provide a request that includes an application identifier and a token. The application may be granted access to a network or denied access depending on the outcome of the validation procedures. The granted access may include assignment of a network slice. The application certificate, a secured token, and a secured attestation value may be stored in a secure environment at the end device and used for validation procedures.
-
公开(公告)号:US11825309B2
公开(公告)日:2023-11-21
申请号:US17511938
申请日:2021-10-27
Applicant: Verizon Patent and Licensing Inc.
Inventor: David Robert Lenrow , Kalyani Bogineni , Vinod Kumar Choyi , Jeffrey Melrose , Yousif Targali , Deepa Jagannatha
IPC: H04W12/088 , H04L12/801 , H04W12/06 , H04W12/37 , H04L47/12 , H04W8/04
CPC classification number: H04W12/088 , H04L47/12 , H04W8/04 , H04W12/06 , H04W12/37
Abstract: Systems and methods described herein enforce access controls for network slices via proxy in a secure enclave of a user equipment (UE) device. A UE device executes, in a rich execution environment (REE), a function or application designated for using one or more secure network slices of a telecommunications network. The UE device executes, in a trusted execution environment (TEE), a slice admission control proxy (SACP) to perform admission control for the one or more secure network slices, and forces network traffic for the function or application through the SACP.
-
-
-
-
-
-
-
-
-