Method and apparatus relating to authenticating digital certificate of encryption key of entity implementing one or more network functions of core network of mobile communication system
By managing and verifying digital certificates in the core network of the mobile communication system, ensuring that the encryption key has a designated purpose, the problem of encryption key interaction security in the core network is solved, and secure connection and key verification between network functional entities are realized.
Patent Information
- Application Number
- CN202380070903.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-10-03
- Filing Date
- 2023-08-08
- Publication Date
- 2025-05-13
AI Technical Summary
When the core network of the mobile communication system realizes encryption key interaction between network functional entities, it lacks effective digital certificate management and authentication mechanisms, making it difficult to achieve secure connection and key verification.
By realizing the generation, transmission and verification of digital certificates in the core network of the mobile communication system, it is ensured that the encryption key of digital certificate authentication has one or more purpose indications, and decisions on secure connection and key operations are made based on these purpose indications.
It realizes that in the core network of the mobile communication system, the secure interaction and verification of encryption keys is ensured through digital certificates, and the secure connection and data transmission reliability between network functional entities are enhanced.
Smart Images

Figure CN119999250A_ABST
Abstract
Description
Technical Field
[0001] Example embodiments relate to apparatus, methods and computer programs, and in particular, but not limited to, to apparatus, methods and computer programs related to digital certificates authenticating cryptographic keys of entities implementing one or more functions of a core network of a mobile communication system. Background Art
[0002] The core network of the mobile communication system may adopt a service-based architecture (SBA), according to which communication between network functions uses a service-based interface (SBI). Interactions between entities implementing network functions of the core network may use encryption keys. Summary of the invention
[0003] A method comprises: receiving, at a first entity implementing at least a first network function of a core network of a mobile communication system, a digital certificate authenticating an encryption key of the first entity; wherein the digital certificate indicates one or more purposes for which the digital certificate authenticates the encryption key; and sending the digital certificate from the first entity to a second entity implementing at least a second network function of the core network of the mobile communication system.
[0004] The one or more purposes may include one or more of: establishing a secure logical connection between the first entity and the second entity; or verifying a client credential assertion token; or verifying an access token; or verifying a service request.
[0005] The digital certificate may conform to the ITU-T X.509 standard for public key infrastructure.
[0006] A digital certificate may include fields populated by one or more identifier values indicating one or more purposes.
[0007] A digital certificate may include a field that supports free text, and the field includes free text indicating one or more purposes.
[0008] Fields that support free text can also indicate a subject name.
[0009] Sending the digital certificate from the first entity to the second entity may be used at least to: establish a secure connection between the first entity and the second entity using at least an encryption key of the first entity; and the one or more purposes may include establishing a secure connection between the first entity and the second entity.
[0010] The method may further include requesting a service opened by the second entity via a secure logical connection between the first entity and the second entity.
[0011] Requesting the service may include sending a digital signature of a token for accessing the service, wherein the digital signature is verifiable at the second entity using an encryption key of the first entity.
[0012] The method may include requesting a digital certificate from a certificate authority.
[0013] A method comprises: receiving, at a second entity implementing at least a second network function of a core network of a mobile communication system, a digital certificate from a first entity implementing at least a first network function of a core network of a mobile communication system, the digital certificate comprising an indication of one or more purposes of the digital certificate authenticating an encryption key of the first entity; and determining, at the second entity, whether to proceed with one or more operations involving the encryption key of the first entity based at least in part on the indication of the one or more purposes.
[0014] The method may also include determining, based at least in part on the indication of the one or more purposes, whether to establish a secure logical connection between the first entity and the second entity using at least an encryption key of the first entity.
[0015] The method may include receiving a digitally signed service request including a service access token from a first entity, and determining, based at least in part on an indication of one or more purposes, whether a cryptographic key is authenticated for use in verifying the digital signature.
[0016] The method may include determining whether to request the first entity to request an access token on behalf of the second entity based at least in part on the indication of the one or more purposes.
[0017] A method includes: receiving a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and issuing a digital certificate including an indication of one or more purposes.
[0018] The method may include sending a digital certificate to a first entity or an entity implementing operation, management and maintenance functions of a core network of a mobile communication system.
[0019] A method comprises: sending a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and receiving a digital certificate including an indication of one or more purposes.
[0020] The sending and receiving may be performed at an entity that implements the operation, management, and maintenance functions of the core network, and the method may further include: sending a digital certificate from the entity that implements the operation, management, and maintenance functions of the core network to the first entity.
[0021] A first entity implementing at least a first network function of a core network of a mobile communication system, the first entity comprising: a component for receiving a digital certificate for authenticating an encryption key of the first entity; wherein the digital certificate indicates one or more purposes of the digital certificate authenticating the encryption key; and a component for sending the digital certificate to a second entity implementing at least a second network function of the core network of the mobile communication system.
[0022] The one or more purposes may include one or more of: establishing a secure logical connection between the first entity and the second entity; or verifying a client credential assertion token; or verifying an access token; or verifying a service request.
[0023] The digital certificate may conform to the ITU-T X.509 standard for public key infrastructure.
[0024] A digital certificate may include fields populated by one or more identifier values indicating one or more purposes.
[0025] A digital certificate may include a field that supports free text, and the field includes free text indicating one or more purposes.
[0026] Fields that support free text can also indicate a subject name.
[0027] Sending a digital certificate from a first entity to a second entity may be used at least to: establish a secure connection between the first entity and the second entity using at least an encryption key of the first entity; and wherein one or more purposes include establishing a secure connection between the first entity and the second entity.
[0028] The first entity may further include means for requesting a service opened by the second entity via a secure logical connection between the first entity and the second entity.
[0029] Requesting the service may include sending a digital signature of a token for accessing the service, wherein the digital signature is verifiable at the second entity using an encryption key of the first entity.
[0030] The first entity may include means for requesting a digital certificate from a certificate authority.
[0031] A second entity implementing at least a second network function of a core network of a mobile communication system, the second entity comprising: a component for receiving a digital certificate from a first entity implementing at least a first network function of the core network of the mobile communication system, the digital certificate comprising an indication of one or more purposes of the digital certificate authenticating an encryption key of the first entity; and a component for determining whether to continue one or more operations involving the encryption key of the first entity based at least in part on the indication of the one or more purposes.
[0032] The second entity may also include means for determining whether to establish a secure logical connection between the first entity and the second entity using at least an encryption key of the first entity based at least in part on the indication of the one or more purposes.
[0033] The second entity may also include means for receiving a digitally signed service request including a service access token from the first entity, and means for determining whether the cryptographic key is authenticated for verifying the digital signature based at least in part on the indication of one or more purposes.
[0034] The second entity may include means for determining whether to request the first entity to request an access token on behalf of the second entity based at least in part on the indication of the one or more purposes.
[0035] A device includes: a component for receiving a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and a component for issuing a digital certificate including an indication of one or more purposes.
[0036] The apparatus may include means for sending a digital certificate to a first entity or an entity implementing operation, management and maintenance functions of a core network of a mobile communication system.
[0037] A device includes: a component for sending a request to generate a digital certificate, the digital certificate authenticating the encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and a component for receiving a digital certificate including an indication of one or more purposes.
[0038] The apparatus may include an entity implementing operation, management and maintenance functions of a core network, and the apparatus may also include a component for sending a digital certificate to the first entity.
[0039] A first entity implementing at least a first network function of a core network of a mobile communication system, the first entity comprising: at least one processor; and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured to, together with the at least one processor, cause the first entity to execute: receiving a digital certificate authenticating an encryption key of the first entity; wherein the digital certificate indicates one or more purposes of the digital certificate authenticating the encryption key; and sending the digital certificate to a second entity implementing at least a second network function of the core network of the mobile communication system.
[0040] The one or more purposes may include one or more of: establishing a secure logical connection between the first entity and the second entity; or verifying a client credential assertion token; or verifying an access token; or verifying a service request.
[0041] The digital certificate may conform to the ITU-T X.509 standard for public key infrastructure.
[0042] A digital certificate may include fields populated by one or more identifier values indicating one or more purposes.
[0043] A digital certificate may include a field that supports free text, and the field may include free text indicating one or more purposes.
[0044] Fields that support free text can also indicate a subject name.
[0045] Sending a digital certificate from a first entity to a second entity may be used at least to: establish a secure connection between the first entity and the second entity using at least an encryption key of the first entity; and wherein one or more purposes may include establishing a secure connection between the first entity and the second entity.
[0046] The at least one memory and the computer program code may also be configured to, with the at least one processor, cause the first entity to: request a service opened by the second entity via a secure logical connection between the first entity and the second entity.
[0047] Requesting the service may include sending a digital signature of a token for accessing the service, wherein the digital signature is verifiable at the second entity using an encryption key of the first entity.
[0048] The at least one memory and the computer program code may also be configured to, with the at least one processor, cause the first entity to request a digital certificate from a certificate authority.
[0049] A second entity implementing at least a second network function of a core network of a mobile communication system, the second entity comprising: at least one processor; and at least one memory comprising computer program code, wherein the at least one memory and the computer program code are configured to, together with the at least one processor, cause the second entity to execute: receiving a digital certificate from a first entity implementing at least a first network function of the core network of the mobile communication system, the digital certificate comprising an indication of one or more purposes of the digital certificate authenticating an encryption key of the first entity; and determining at the second entity whether to continue one or more operations involving the encryption key of the first entity based at least in part on the indication of the one or more purposes.
[0050] The at least one memory and the computer program code may also be configured to, with the at least one processor, cause the second entity to: determine, based at least in part on an indication of one or more purposes, whether to establish a secure logical connection between the first entity and the second entity using at least an encryption key of the first entity.
[0051] The at least one memory and the computer program code may be configured to, together with the at least one processor, cause the second entity to: receive a service request including a digital signature of a service access token from the first entity, and determine, based at least in part on an indication of one or more purposes, whether a cryptographic key is authenticated for use in verifying the digital signature.
[0052] The at least one memory and the computer program code may be configured to, with the at least one processor, cause the second entity to: determine whether to request the first entity to request an access token on behalf of the second entity based at least in part on the indication of one or more purposes.
[0053] A device comprises: at least one processor; and at least one memory comprising computer program code, wherein the at least one memory and the computer program code are configured to, together with the at least one processor, cause the device to execute: receiving a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and issuing a digital certificate including an indication of the one or more purposes.
[0054] The at least one memory and the computer program code may be configured to, together with the at least one processor, cause the apparatus to: send a digital certificate to a first entity or an entity implementing operation, management and maintenance functions of a core network of a mobile communication system.
[0055] A device includes: at least one processor; and at least one memory including computer program code, wherein the at least one memory and the computer program code are configured to, together with the at least one processor, cause the device to execute: sending a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and receiving a digital certificate including an indication of one or more purposes.
[0056] The apparatus may be an entity implementing operation, management and maintenance functions of a core network, and the at least one memory and the computer program code may be configured to, together with the at least one processor, cause the apparatus to: send a digital certificate to a first entity.
[0057] A first entity implementing at least a first network function of a core network of a mobile communication system comprises: a receiving circuit system for receiving a digital certificate for authenticating an encryption key of the first entity; wherein the digital certificate indicates one or more purposes of the digital certificate authenticating the encryption key; and a sending circuit system for sending the digital certificate to a second entity implementing at least a second network function of the core network of the mobile communication system.
[0058] A second entity implementing at least a second network function of a core network of a mobile communication system includes: a receiving circuit system for receiving a digital certificate from a first entity implementing at least a first network function of the core network of the mobile communication system, the digital certificate including an indication of one or more purposes of the digital certificate authenticating an encryption key of the first entity; and a determining circuit system for determining whether to continue one or more operations involving the encryption key of the first entity based at least in part on the indication of the one or more purposes.
[0059] A device includes: a receiving circuit system for receiving a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and issuing a digital certificate including an indication of one or more purposes.
[0060] A device includes: a sending circuit system for sending a request to generate a digital certificate, wherein the digital certificate authenticates an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and a receiving circuit system for receiving a digital certificate including an indication of one or more purposes.
[0061] A computer-readable medium having stored thereon program instructions for performing the following: receiving, at a first entity implementing at least a first network function of a core network of a mobile communication system, a digital certificate authenticating an encryption key of the first entity; wherein the digital certificate indicates one or more purposes for which the digital certificate authenticates the encryption key; and sending the digital certificate from the first entity to a second entity implementing at least a second network function of the core network of the mobile communication system.
[0062] A computer-readable medium having stored thereon program instructions for performing the following: receiving, at a second entity implementing at least a second network function of a core network of a mobile communication system, a digital certificate from a first entity implementing at least a first network function of a core network of a mobile communication system, the digital certificate including an indication of one or more purposes of the digital certificate authenticating an encryption key of the first entity; and determining, at the second entity, whether to continue one or more operations involving the encryption key of the first entity based at least in part on the indication of the one or more purposes.
[0063] A computer-readable medium having stored thereon program instructions for performing the following: receiving a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and issuing a digital certificate including an indication of the one or more purposes.
[0064] A computer-readable medium having stored thereon program instructions for performing the following: sending a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and receiving a digital certificate including an indication of one or more purposes.
[0065] A non-transitory computer-readable medium includes program instructions stored thereon for performing the following: receiving, at a first entity implementing at least a first network function of a core network of a mobile communication system, a digital certificate authenticating an encryption key of the first entity; wherein the digital certificate indicates one or more purposes for which the digital certificate authenticates the encryption key; and sending the digital certificate from the first entity to a second entity implementing at least a second network function of the core network of the mobile communication system.
[0066] A non-transitory computer-readable medium includes program instructions stored thereon for performing the following: receiving, at a second entity implementing at least a second network function of a core network of a mobile communication system, from a first entity implementing at least a first network function of a core network of a mobile communication system, the digital certificate including an indication of one or more purposes for the digital certificate to authenticate an encryption key of the first entity; and determining, at the second entity, whether to continue one or more operations involving the encryption key of the first entity based at least in part on the indication of the one or more purposes.
[0067] A non-transitory computer-readable medium includes program instructions stored thereon for performing the following: receiving a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and issuing a digital certificate including an indication of the one or more purposes.
[0068] A non-transitory computer-readable medium includes program instructions stored thereon for performing the following: sending a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and receiving a digital certificate including an indication of one or more purposes.
[0069] A computer program includes computer executable code, which, when executed on at least one processor, is configured to cause a first entity implementing at least a first network function of a core network of a mobile communication system to at least: receive a digital certificate authenticating an encryption key of the first entity; wherein the digital certificate indicates one or more purposes for which the digital certificate authenticates the encryption key; and send the digital certificate to a second entity implementing at least a second network function of the core network of the mobile communication system.
[0070] A computer program includes computer executable code, which, when executed on at least one processor, is configured to cause a second entity implementing at least a second network function of a core network of a mobile communication system to at least: receive a digital certificate from a first entity implementing at least a first network function of the core network of the mobile communication system, the digital certificate including an indication of one or more purposes of the digital certificate authenticating an encryption key of the first entity; and determine, at the second entity, whether to continue one or more operations involving the encryption key of the first entity based at least in part on the indication of the one or more purposes.
[0071] A computer program includes computer executable code, which, when executed on at least one processor, is configured to cause a device to at least: receive a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and issue a digital certificate including an indication of the one or more purposes.
[0072] A computer program includes computer executable code, which, when running on at least one processor, is configured to cause a device to at least: send a request to generate a digital certificate, the digital certificate authenticating an encryption key of a first entity that implements one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes of the digital certificate authenticating the encryption key; and receive a digital certificate including an indication of one or more purposes.
[0073] In the above, many different aspects have been described. It should be understood that other aspects can be provided by combining any two or more of the above aspects.
[0074] Various other aspects are also described in the following detailed description and appended claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] Some example embodiments will now be described in more detail, by way of example only, with reference to the following examples and accompanying drawings, in which:
[0076] Figure 1 An example mobile communication system is shown in which some example embodiments may be applied;
[0077] Figure 2 According to some example embodiments Figure 1 representation of examples of operations on some elements of;
[0078] Figure 3 According to some example embodiments Figure 1 representation of examples of operations on some elements of;
[0079] Figure 4 According to some example embodiments Figure 1 representation of examples of operations on some elements of;
[0080] Figure 5 According to some example embodiments Figure 1 representation of examples of operations on some elements of;
[0081] Figure 6 According to some example embodiments Figure 1 representation of examples of operations on some elements of;
[0082] Figure 7 According to some example embodiments Figure 1 representation of examples of operations on some elements of;
[0083] Figure 8 A representation showing an example of an apparatus for implementing core network functions according to some example embodiments; and
[0084] Fig. 9 A representation of an example of a non-volatile storage medium is shown. DETAILED DESCRIPTION
[0085] For example, the following description focuses on an example of a mobile communication system operating according to 3GPP 5G technology, but the underlying technology may also be applicable to systems operating according to other technologies (such as more evolved 3GPP technologies).
[0086] Figure 1 A simple representation of one example of a 3GPP 5G system architecture is shown. Figure 1 All cells shown are logic cells. Figure 1 The connections shown are logical connections; the actual physical connections may be different. 5G systems may include Figure 1 Other functions and structures than those shown.
[0087] The core network can provide connectivity between devices implementing user equipment functions (UE) and one or more data networks (DNs) via a new generation radio access network (NG-RAN), which includes a network of devices implementing instances of gNodeB (gNB) functions.
[0088] The gNB is (i) connected to the User Plane Function (UPF) of the Core Network (CN) for routing and forwarding user data packets and for providing connectivity of the device to one or more external packet data networks (DNs), and (ii) connected to the Access Mobility Management Function (AMF) of the Core Network (CN) for controlling access and change of the UE's serving cell.
[0089] The term "user equipment" (UE) may refer to any device, apparatus or component that implements at least 3GPP user equipment (UE) functionality.
[0090] A UE may be a mobile or static device (e.g., a portable or non-portable computing device), including but not limited to the following types of devices: mobile phones, smartphones, personal digital assistants (PDAs), cell phones, devices using wireless modems (alarm or measurement devices, etc.), laptops and / or touch screen computers, tablets, game consoles, notebook computers, and multimedia devices. It should be understood that a UE device may also be an almost exclusively uplink-only device, an example of which is a camera or video camera that loads images or video clips to a network. A UE device may also be a device with the ability to operate in an Internet of Things (IoT) network, which enables a scenario in which objects are able to transmit data over a network without requiring human-to-human interaction or human-to-computer interaction, such as for use in smart grids and connected vehicles. The device may also use the cloud. In some applications, the device may include a user-portable device with a radio component (such as a watch, headphones, or glasses), and the computation is performed in the cloud.
[0091] 5G enables the use of multiple-input multiple-output (MIMO) antennas and may involve a large number of base stations (gNBs), including macro sites that operate in cooperation with smaller sites and use various radio technologies depending on service requirements, use cases and / or available spectrum. 5G mobile communications support a wide range of use cases and related applications, including video streaming, augmented reality, different data sharing methods, and various forms of machine-type applications (such as (massive) machine-type communications (mMTC), including vehicle safety, different sensors, and real-time control). 5G can use multiple frequency bands, such as below 6GHz or above 24GHz, cmWave, and mmWave, and can also be integrated with existing traditional radio access technologies such as long-term evolution (LTE). Integration with LTE can be implemented as a system in which macro coverage is provided by LTE and 5G radio interface access comes from small cells by aggregation to LTE. In other words, 5G can support both inter-RAT operability (such as LTE-5G) and inter-RI operability (inter-radio interface operability, such as below 6GHz-cmWave, 6 or above 24GHz-cmWave, and mmWave). 5G networks can adopt network slicing, in which multiple independent and dedicated virtual subnets (network instances) can be created within the same infrastructure to run services with different requirements for latency, reliability, throughput, and mobility.
[0092] Low-latency applications and services can be facilitated by bringing content closer to 5G systems, enabling local breakout and multi-access edge computing (MEC). 5G enables analysis and knowledge generation to be performed at the data source. This approach can involve leveraging resources that may not be continuously connected to the network, such as laptops, smartphones, tablets, and sensors. MEC provides a distributed computing environment for application and service hosting. It also enables storage and processing of content close to cellular subscribers for faster response times. Edge computing covers a wide range of technologies such as wireless sensor networks, mobile data collection, mobile signature analysis, collaborative distributed peer-to-peer self-organizing networks and processing (also categorized as local cloud / fog computing and grid / mesh computing), dew computing, mobile edge computing, cloudlet, distributed data storage and retrieval, autonomous self-healing networks, remote cloud services, augmented and virtual reality, data caching, Internet of Things (massive connectivity and / or latency critical), critical communications (autonomous vehicles, traffic safety, real-time analysis, time-critical control, healthcare applications).
[0093] 5G can also make use of satellite communications to enhance or supplement the coverage of 5G services, for example by providing backhaul. Possible use cases are to provide service continuity for machine-to-machine (M2M) or Internet of Things (IoT) devices or passengers on board, mobile broadband (MBB), or to ensure service availability for critical communications and future railway / maritime / aeronautical communications. Satellite communications can make use of geostationary orbit (GEO) satellite systems, but also low Earth orbit (LEO) satellite systems, in particular mega-constellations (systems in which hundreds of (nano) satellites are deployed). Each satellite in a mega-constellation can cover several satellite network entities creating a ground cell. A ground cell can be created by a ground relay node, or by a gNB located on the ground or in a satellite.
[0094] 5GC adopts a service-based architecture (SBA), according to which communication between network functions (implemented at the core network entity) uses a service-based interface (SBI). Application programming interfaces (APIs) are used for SBI. Examples of network functions specified by 3GPP include: SCP (Service Communication Broker); Network Repository Function (NRF); Operations Administration and Maintenance (OAM); Certificate Authority (CA); and Security Edge Protection Proxy (SEPP). Figure 1 NF1 and NF2 can be any network functions implemented by the core network entity.
[0095] When using SBA in the core network, the interactions between the core network entities are protected at the transport layer and the application layer. For example, the Transport Layer Security (TLS1.2 and 1.3) protocol can protect the communication between the core network entities at the transport layer; and the OAuth 2.0 framework can protect the communication between the core network entities at the application layer.
[0096] These security protocols may involve the use of cryptographic public (private) key pairs of entities implementing one or more network functions.
[0097] For example, TLS uses asymmetric cryptography (involving the use of at least one public key of at least one interacting core network entity) to securely generate and exchange session keys. The session keys are then used to encrypt and decrypt data sent between the interacting core network entities.
[0098] A digital certificate issued by a certificate authority (CA) can assert the authenticity of a public key.
[0099] The public key of a core network entity that implements one or more network functions can also be used, for example, to verify the digital signature of an OAuth token at a receiving core network entity, which OAuth token protects communications between core network entities at the application layer; and, for example, to protect messages sent by an entity of one core network (for one public land mobile network (PLMN)) to an entity of another core network (for another PLMN) via an entity that implements a security edge protection proxy (SEPP) function.
[0100] The application layer security solution on the N32 interface provides protection for the communication between SEPPs of the corresponding core network.
[0101] Figure 2 The present invention illustrates a method according to some example embodiments. Figure 1 Examples of operations at elements of .
[0102] A core network entity implementing OAM for the operator of PLMN1 sends a request for a digital certificate of the public key of a terminal entity implementing NF1 to a CA server of the core network (operation 200). The request specifies one or more purposes for which the NF1 key is to be certified.
[0103] In response to the request, the CA server generates a digital certificate for the NF1 key (operation 210). The certificate indicates one or more purposes specified in the request from the OAM.
[0104] The CA server sends a digital certificate issued by the CA server to a core network entity implementing OAM (operation 220).
[0105] The core network entity implementing OAM sends a digital certificate to a core network terminal entity (EE) implementing NF1 (operation 230).
[0106] Figure 3 The present invention illustrates a method according to some example embodiments. Figure 1 Another example of an operation at an element of .
[0107] A core network entity implementing OAM for the operator of PLMN1 sends an indication to the EE implementing NF1 of one or more purposes for which operator policy allows the use of NF1's public key (operation 300).
[0108] NF1 sends a request for a digital certificate of NF1's public key to the CA server (operation 310). The request to the CA server indicates the purpose indicated in the message from OAM to NF1.
[0109] The CA server generates a digital certificate for NF1's public key (operation 320). The digital certificate issued by the CA server for NF1's public key includes an indication of one or more purposes indicated in the request from NF1.
[0110] The CA server sends the digital certificate to NF1 (operation 330).
[0111] Figure 4 The present invention illustrates a method according to some example embodiments. Figure 1 Examples of operations at elements of . Figure 4 An example relates to an operator policy according to which the public key of the example network function NF1 is restricted to use only when creating a TLS connection with another core network entity.
[0112] The CA server stores information about operator policies regarding the use of public keys by entities of the core network, including the EE implementing NF1 (operation 400).
[0113] The EE implementing NF1 sends a request for a digital certificate of NF1's public key to the CA server (operation 410). The request from NF1 specifies that the public key is to be used to establish a TLS connection between NF1 (as a client) and another core network entity (as a server).
[0114] Based on information about the operator policy stored at the CA server, the CA server determines that the operator policy allows a public key certificate for a specified purpose to be issued to NF1, and generates a digital certificate including an indication that the digital certificate certifies the public key for the specified purpose (operation 420).
[0115] The CA server sends the issued digital certificate to NF1 (operation 430).
[0116] Figure 5 An example of subsequent operations of NF1 and another example network function NF2 according to some example embodiments is illustrated.
[0117] NF1 sends a request for a TLS connection with NF2 to NF2 (operation 500). The request includes a digital certificate issued by the CA server for NF1's public key.
[0118] NF2 reads the indication of purpose included in the digital certificate and determines that the digital certificate does authenticate the NF1 public key for the purpose of establishing a TLS connection (operation 510).
[0119] Using the TLS connection established with NF2, NF1 sends a request to NF2 for a service opened by NF2 (operation 520). The request includes a digital certificate issued by the CA server for NF1's public key. The request also includes a client credential assertion (CCA).
[0120] NF2 reads the indication of the purpose in the digital certificate again. NF2 determines that the digital certificate does not authenticate NF1's public key for the purpose of verifying the CCA. Therefore, NF2 determines to deny the service request from NF1 (operation 530).
[0121] NF2 sends a service response including an error code to NF1.
[0122] Figure 6 The present invention illustrates a method according to some example embodiments. Figure 1 Another example of an operation at an element of .
[0123] The entity implementing the NRF for the core network is configured with a digital certificate that authenticates the public key of the NRF for two purposes: (i) establishing a TLS connection with another core network entity; and (ii) access token signing (operation 600).
[0124] The NRF establishes a TLS connection with NF1 using the NRF public key (operation 610).
[0125] NF1 stores the digital certificate of the NRF public key (operation 620).
[0126] NF1 determines to consume a service exposed by another network function NF2 discovered via NRF. Based on the indication of the purpose in the digital certificate of the public key of NRF, NF1 determines to obtain an access token required to consume the service exposed by NF2 from NRF (operation 640).
[0127] exist Figure 6 In the example of NFc, the producer network function (NFp) belongs to the same core network (same PLMN) as the consumer network function (NFc). In an alternative example where NFc and NFp belong to different core networks (different PLMNs), two NRF functions may be involved: NRFc, which belongs to the same core network as NFc and via which NFc discovers NFp; and NRFp, which belongs to the same core network as NFp and which can sign the access token requesting the service from NFp. In this alternative example, NRFc checks the digital certificate against the public key of NRFp, and only requests an access token from NRFp to request a service from NFp if the digital certificate authenticates the public key of NRFp for the purpose of signing the access token.
[0128] Figure 7Illustrated are examples of operations at a core network entity according to some example embodiments.
[0129] A core network entity receives a digital certificate for a public key of another core network entity, step 700. The digital certificate includes an indication of the purpose for which the certificate authenticates the public key of the other core network entity.
[0130] The receiving core network entity determines whether to proceed with an operation involving the public key of another core network entity based at least in part on the indication of the purpose included in the digital certificate (step 710). For example, the operation involving the public key of another core network entity may be: establishing a TLS connection with another core network entity; protecting an access token by a digital signature verifiable by a public key; protecting an o-auth token by a digital signature verifiable by a public key.
[0131] In response to a positive determination, the receiving core network entity continues to operate (step 720). In response to a negative determination, the receiving core network entity does not continue to operate (step 730).
[0132] The above examples relate to general network functions NF1 and NF2. The network function receiving and checking the indication of the purpose of the public key in the digital certificate and / or the network function to which the public key belongs may be a specific function defined by 3GPP, such as for example SCP or SEPP.
[0133] For example, the above techniques may involve enhancing digital certificates compliant with the ITU-TX.509 standard for public key infrastructure, the structure of which is defined by RFC5280.
[0134] According to one example, the enhancement includes defining a new purpose ID for the existing extendedKeyUsage field of the X.509 digital certificate structure. An example of a new purpose ID is listed below. id-kp-CCASigning OBJECT IDENTIFIER::={id-kp10}
[0135] --Sign the CCA token
[0136] --Can use the same key bit: digitalSignature
[0137] -- and / or non-repudiation
[0138] id-kp-OATUHSigning OBJECT IDENTIFIER::=
[0139] {id-kp 11}
[0140] --Sign the o-auth access token
[0141] --Can use the same key bit: digitalSignature
[0142] -- and / or non-repudiation
[0143] id-kp-SEPPDataEncryption OBJECT IDENTIFIER::={id-kp12}
[0144] --Encrypt SEPP message
[0145] --Can use the same key bit: digitalSignature
[0146] -- and / or non-repudiation
[0147] Additionally or alternatively, the free text of the existing subjectAltName (SAN) field of the X.509 digital certificate structure is used to indicate one or more purposes for which the certificate authenticates the NF public key. According to one example, the CA server adds to the SAN field an indication of the purpose specified in the certificate request (CSR / IR) from the NF using an automatic enrollment protocol such as CMPv2. According to another example, the operator may manually obtain a certificate that already contains the purpose indication(s) in the SAN field.
[0148] According to one example, the SAN field may be enhanced to include a destination string. An example is listed below.
[0149] <purpose-list> NF_TLS_CLIENT, NF_TLS_SERVER, ACCESSTOKEN_SIGNING, CCA_SIGNING< / purpose-list>
[0150] According to one example, the SAN field contains the PURPOSE-LIST defined above as a URN (Uniform Resource Name) in a URI (Uniform Resource Identifier).
[0151] According to another example, one or more purposes of the certificate authenticating the NF public key are indicated in another existing field of the X.509 digital certificate structure, or in a new field dedicated to identifying one or more purposes of the certificate authenticating the NF private key.
[0152] The above techniques help prevent violations of CA policies and help reduce the risk of cross-protocol attacks. The above techniques help prevent NFs from obtaining certificates that could be abused for tasks that the NF is not authorized to perform. For example, the above techniques can help prevent a consumer function from impersonating a producer function using its own client certificate.
[0153] Figure 8 The diagram shows the Figure 1The apparatus may include at least one processor 802 coupled to one or more interfaces 808 for communicating with one or more entities implementing other core network functions. The at least one processor 802 may also be coupled to at least one memory 806. The at least one processor 802 may be configured to execute appropriate software code to perform the above operations. The software code may be stored in the memory 806.
[0154] Fig. 9 Schematic diagrams of non-volatile storage media 900a (e.g., a computer compact disc (CD) or digital versatile disc (DVD)) and 900b (e.g., a universal serial bus (USB) memory stick) storing instructions and / or parameters 902 that, when executed by a processor, enable the processor to perform one or more steps of the previously described method.
[0155] It should be noted that the example embodiments may be implemented as circuitry in software, hardware, application logic, or a combination of software, hardware, and application logic. In the example embodiments, the application logic, software, or instruction set is maintained on any computer-readable medium. In the context of this document, a "computer-readable medium" may be any medium or component that can contain, store, communicate, propagate, or transport instructions for use by or in conjunction with an instruction execution system, apparatus, or device (such as a base station or user equipment of the above example embodiments).
[0156] As used in this application, the term "circuitry" refers to all of the following: (a) pure hardware circuit implementations (such as implementations in analog and / or digital circuitry only), and (b) combinations of circuits and software (and / or firmware), such as (as applicable): (i) a combination of (multiple) processors or (ii) portions of (multiple) processors / software (including (multiple) digital signal processors), software, and (multiple) memories that work together to cause a device (such as the user equipment or base station of the above embodiments) to perform various functions), and (c) circuits, such as (multiple) microprocessors or portions of (multiple) microprocessors, that require software or firmware to run, even if the software or firmware is not physically present. This definition of "circuitry" applies to all uses of the term in this application, including in any claims. As another example, as used in this application, the term "circuitry" would also cover implementations of only a processor (or multiple processors) or a portion of a processor and its accompanying software and / or firmware. For example, if applicable to a particular claim element, the term "circuitry" would also cover a baseband integrated circuit or application processor integrated circuit for a mobile phone, or a similar integrated circuit in a server, cellular network device, or other network device.
[0157] The features, advantages and characteristics described herein may be combined in any suitable manner in one or more example embodiments. Those skilled in the relevant art will recognize that such example embodiments may be practiced without one or more specific features or advantages of a particular embodiment. In other cases, additional features and advantages that may not be present in all example embodiments may be recognized in certain embodiments. It will be readily appreciated by those of ordinary skill in the art that the example embodiments described above may be practiced with steps in different orders and / or with hardware elements of configurations different from the disclosed configurations. Therefore, although some embodiments have been described based on these example embodiments, it will be appreciated by those skilled in the art that certain modifications, variations and alternative constructions will be clear while still within the spirit and scope of the example embodiments.
Claims
1. A method comprising: receiving, at a first entity, a digital certificate authenticating an encryption key for the first entity, the first entity implementing at least a first network function for a core network of a mobile communication system; wherein the digital certificate indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as The digital certificate is sent from the first entity to a second entity, the second entity implementing at least a second network function for the core network of the mobile communication system.
2. The method of claim 1, wherein the one or more purposes include one or more of: establishing a secure logical connection between the first entity and the second entity; or verifying a client credential assertion token; or verifying an access token; or verifying a service request.
3. A method according to any preceding claim, wherein the digital certificate complies with the ITU-T X.509 standard for public key infrastructure.
4. A method according to any preceding claim, wherein the digital certificate comprises a field populated by one or more identifier values indicating the one or more purposes.
5. A method according to any preceding claim, wherein the digital certificate comprises a field supporting free text, and the field comprises free text indicating the one or more purposes. The method of claim 5 , wherein the field supporting free text also indicates a subject name.
7. A method according to any preceding claim, wherein sending the digital certificate from the first entity to the second entity is used at least for: establishing a secure connection between the first entity and the second entity using at least the encryption key of the first entity; and wherein the one or more purposes include establishing a secure connection between the first entity and the second entity.
8. The method according to claim 7, further comprising: A service opened by the second entity is requested via the secure logical connection between the first entity and the second entity.
9. The method of claim 8, wherein requesting the service comprises: A digital signature of a token for accessing the service is sent, wherein the digital signature is verifiable at the second entity using the encryption key of the first entity.
10. A method according to any preceding claim, comprising: Request the digital certificate from a certificate authority.
11. A method comprising: receiving, at a second entity, a digital certificate from a first entity, the first entity implementing at least a first network function for a core network of a mobile communication system, the second entity implementing at least a second network function for the core network of the mobile communication system, the digital certificate comprising an indication of one or more purposes, the digital certificate authenticating an encryption key for the first entity for the one or more purposes; as well as Based at least in part on the indication of the one or more purposes, a determination is made at the second entity whether to proceed with one or more operations involving the cryptographic key of the first entity.
12. The method according to claim 11, further comprising: Based at least in part on the indication of the one or more purposes, a determination is made whether to establish a secure logical connection between the first entity and the second entity using at least the encryption key of the first entity.
13. The method according to claim 12, comprising: A service request is received from the first entity, the service request comprising a digital signature for a service access token, and based at least in part on the indication of the one or more purposes, a determination is made whether the encryption key is authenticated for verifying the digital signature.
14. The method according to claim 11, comprising: Based at least in part on the indication of the one or more purposes, a determination is made whether to request the first entity to request an access token on behalf of the second entity.
15. A method comprising: receiving a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as A digital certificate is issued including an indication of the one or more purposes.
16. The method according to claim 15, comprising: The digital certificate is sent to the first entity or an entity that implements operation, management and maintenance functions of the core network for the mobile communication system.
17. A method comprising: sending a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as A digital certificate including an indication of the one or more purposes is received.
18. The method according to claim 17, wherein the sending and the receiving are performed at an entity implementing an operation, management, and maintenance function for the core network, and the method further comprises: The digital certificate is sent from the entity implementing operation, management and maintenance functions for the core network to the first entity.
19. A first entity for implementing at least a first network function of a core network for a mobile communication system, the first entity comprising: means for receiving a digital certificate authenticating an encryption key for said first entity; wherein the digital certificate indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as A component for sending the digital certificate to a second entity, the second entity at least implementing a second network function for the core network of the mobile communication system.
20. The first entity of claim 19, wherein the one or more purposes include one or more of: establishing a secure logical connection between the first entity and the second entity; or verifying a client credential assertion token; or verifying an access token; or verifying a service request.
21. A first entity according to claim 19 or claim 20, wherein the digital certificate complies with the ITU-T X.509 standard for public key infrastructure.
22. The first entity according to any one of claims 19 to 21, wherein the digital certificate comprises a field populated by one or more identifier values indicating the one or more purposes.
23. The first entity of any one of claims 19 to 22, wherein the digital certificate comprises a field supporting free text, and the field comprises free text indicating the one or more purposes.
24. The first entity of claim 23, wherein the field supporting free text also indicates a subject name.
25. A first entity according to any one of claims 19 to 24, wherein sending the digital certificate to the second entity is used at least for the following items: establishing a secure connection between the first entity and the second entity using at least the encryption key of the first entity; and wherein the one or more purposes include establishing a secure connection between the first entity and the second entity.
26. The first entity of claim 25, further comprising: Means for requesting, via the secure logical connection between the first entity and the second entity, a service exposed by the second entity.
27. The first entity of claim 26, wherein requesting the service comprises: A digital signature of a token for accessing the service is sent, wherein the digital signature is verifiable at the second entity using the encryption key of the first entity.
28. A first entity according to any one of claims 19 to 27, comprising: Means for requesting said digital certificate from a certificate authority.
29. A second entity implementing at least a second network function of a core network for a mobile communication system, the second entity comprising: means for receiving a digital certificate from a first entity, the first entity implementing at least a first network function for the core network of the mobile communications system, the digital certificate comprising an indication of one or more purposes for which the digital certificate authenticates an encryption key for the first entity; as well as Means for determining whether to proceed with one or more operations involving the cryptographic key of the first entity based at least in part on the indication of the one or more purposes.
30. The second entity according to claim 29, further comprising: Means for determining whether to establish a secure logical connection between the first entity and the second entity using at least the encryption key of the first entity based at least in part on the indication of the one or more purposes.
31. The second entity according to claim 30, comprising: means for receiving a service request from the first entity, the service request comprising a digital signature for a service access token; and means for determining, based at least in part on the indication of the one or more purposes, whether the cryptographic key is authenticated for use in verifying the digital signature.
32. The second entity according to claim 29, comprising: Means for determining whether to request the first entity to request an access token on behalf of the second entity based at least in part on the indication of the one or more purposes.
33. An apparatus comprising: means for receiving a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; as well as Means for issuing a digital certificate including an indication of the one or more purposes.
34. The apparatus according to claim 33, comprising: A component for sending the digital certificate to the first entity or an entity implementing operation, management and maintenance functions of the core network for the mobile communication system.
35. An apparatus comprising: means for sending a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; as well as Means for receiving a digital certificate including an indication of the one or more purposes.
36. The apparatus of claim 35, wherein the apparatus comprises an entity implementing operation, management, and maintenance functions for the core network, and the apparatus further comprises means for sending the digital certificate to the first entity.
37. A first entity implementing at least a first network function of a core network for a mobile communication system, the first entity comprising: at least one processor; as well as at least one memory comprising computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause the first entity to execute: receiving a digital certificate authenticating an encryption key for the first entity; wherein the digital certificate indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as The digital certificate is sent to a second entity, the second entity at least implementing a second network function of the core network for the mobile communication system.
38. The first entity of claim 37, wherein the one or more purposes include one or more of: establishing a secure logical connection between the first entity and the second entity; or verifying a client credential assertion token; or verifying an access token; or verifying a service request.
39. A first entity according to claim 37 or claim 38, wherein the digital certificate complies with the ITU-T X.509 standard for public key infrastructure.
40. The first entity according to any one of claims 37 to 39, wherein the digital certificate comprises a field populated by one or more identifier values indicating the one or more purposes.
41. A first entity according to any one of claims 37 to 40, wherein the digital certificate comprises a field supporting free text, and the field comprises free text indicating the one or more purposes.
42. The first entity of claim 41, wherein the field supporting free text also indicates a subject name.
43. A first entity according to any one of claims 37 to 42, wherein sending the digital certificate to the second entity is used at least for: establishing a secure connection between the first entity and the second entity using at least the encryption key of the first entity; and wherein the one or more purposes include establishing a secure connection between the first entity and the second entity.
44. The first entity according to claim 43, wherein the at least one memory and the computer program code are further configured to, together with the at least one processor, cause the first entity to: request a service opened by the second entity via the secure logical connection between the first entity and the second entity.
45. The first entity of claim 44, wherein requesting the service comprises: A digital signature of a token for accessing the service is sent, wherein the digital signature is verifiable at the second entity using the encryption key of the first entity.
46. The first entity according to any one of claims 37 to 45, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the first entity to request the digital certificate from a certificate authority.
47. A second entity implementing at least a second network function of a core network for a mobile communication system, the second entity comprising: at least one processor; as well as at least one memory comprising computer program code, the at least one memory and the computer program code being configured to, together with the at least one processor, cause the second entity to execute: receiving a digital certificate from a first entity, the first entity implementing at least a first network function for the core network of the mobile communication system, the digital certificate comprising an indication of one or more purposes, the digital certificate authenticating an encryption key for the first entity for the one or more purposes; as well as Based at least in part on the indication of the one or more purposes, a determination is made at the second entity whether to proceed with one or more operations involving the cryptographic key of the first entity.
48. A second entity according to claim 47, wherein the at least one memory and the computer program code are also configured to, together with the at least one processor, enable the second entity to: determine, at least in part based on the indication of the one or more purposes, whether to establish a secure logical connection between the first entity and the second entity using at least the encryption key of the first entity.
49. A second entity according to claim 48, wherein the at least one memory and the computer program code are configured to, together with the at least one processor, cause the second entity to: receive a service request from the first entity, the service request comprising a digital signature for a service access token, and determine whether the encryption key is authenticated for verifying the digital signature based at least in part on the indication of the one or more purposes.
50. A second entity according to claim 47, wherein the at least one memory and the computer program code are configured to, together with the at least one processor, cause the second entity to: determine whether to request the first entity to request an access token on behalf of the second entity based at least in part on the indication of the one or more purposes.
51. An apparatus comprising: at least one processor; as well as at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause the apparatus to perform: Receiving a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; as well as A digital certificate is issued including an indication of the one or more purposes.
52. An apparatus according to claim 51, wherein the at least one memory and the computer program code are configured to, together with the at least one processor, enable the apparatus to: send the digital certificate to the first entity or an entity that implements operation, management and maintenance functions of the core network for the mobile communication system.
53. An apparatus comprising: at least one processor; as well as at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause the apparatus to perform: sending a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; as well as A digital certificate including an indication of the one or more purposes is received.
54. An apparatus according to claim 53, wherein the apparatus is an entity that implements operation, management and maintenance functions for the core network, and the at least one memory and the computer program code are configured to, together with the at least one processor, enable the apparatus to: send the digital certificate to the first entity.
55. A first entity implementing at least a first network function of a core network for a mobile communication system, comprising: receiving circuitry for receiving a digital certificate authenticating an encryption key for the first entity; wherein the digital certificate indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as A sending circuit system is used to send the digital certificate to a second entity, and the second entity at least implements a second network function of the core network for the mobile communication system.
56. A second entity implementing at least a second network function for a core network of a mobile communication system, comprising: a receiving circuit system configured to receive a digital certificate from a first entity, the first entity implementing at least a first network function for the core network of the mobile communication system, the digital certificate including an indication of one or more purposes, the digital certificate authenticating an encryption key for the first entity for the one or more purposes; as well as Determining circuitry for determining whether to proceed with one or more operations involving the cryptographic key of the first entity based at least in part on the indication of the one or more purposes.
57. An apparatus comprising: a receiving circuit system configured to receive a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; as well as A digital certificate is issued including an indication of the one or more purposes.
58. An apparatus comprising: a transmitting circuit system configured to transmit a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system, wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; as well as Receiving circuitry is configured to receive a digital certificate including an indication of the one or more purposes.
59. A computer readable medium comprising program instructions stored thereon, the program instructions being configured to: receiving, at a first entity, a digital certificate authenticating an encryption key for the first entity, the first entity implementing at least a first network function for a core network of a mobile communication system; wherein the digital certificate indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as The digital certificate is sent from the first entity to a second entity, the second entity implementing at least a second network function for the core network of the mobile communication system.
60. A computer readable medium comprising program instructions stored thereon, the program instructions being configured to: receiving, at a second entity, a digital certificate from a first entity, the first entity implementing at least a first network function for a core network of a mobile communication system, the second entity implementing at least a second network function for the core network of the mobile communication system, the digital certificate comprising an indication of one or more purposes, the digital certificate authenticating an encryption key for the first entity for the one or more purposes; and Based at least in part on the indication of the one or more purposes, a determination is made at the second entity whether to proceed with one or more operations involving the cryptographic key of the first entity.
61. A computer readable medium comprising program instructions stored thereon, the program instructions being configured to: Receiving a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; and A digital certificate is issued including an indication of the one or more purposes.
62. A computer readable medium comprising program instructions stored thereon, the program instructions being configured to: sending a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; and A digital certificate including an indication of the one or more purposes is received.
63. A non-transitory computer readable medium comprising program instructions stored thereon, the program instructions being configured to: receiving, at a first entity, a digital certificate authenticating an encryption key for the first entity, the first entity implementing at least a first network function for a core network of a mobile communication system; wherein the digital certificate indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as The digital certificate is sent from the first entity to a second entity, the second entity implementing at least a second network function for the core network of the mobile communication system.
64. A non-transitory computer readable medium comprising program instructions stored thereon, the program instructions being configured to: receiving, at a second entity, a digital certificate from a first entity, the first entity implementing at least a first network function for a core network of a mobile communication system, the second entity implementing at least a second network function for the core network of the mobile communication system, the digital certificate comprising an indication of one or more purposes, the digital certificate authenticating an encryption key for the first entity for the one or more purposes; and Based at least in part on the indication of the one or more purposes, a determination is made at the second entity whether to proceed with one or more operations involving the cryptographic key of the first entity.
65. A non-transitory computer readable medium comprising program instructions stored thereon, the program instructions being configured to: Receiving a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; and A digital certificate is issued including an indication of the one or more purposes.
66. A non-transitory computer readable medium comprising program instructions stored thereon, the program instructions being configured to: sending a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; and A digital certificate including an indication of the one or more purposes is received.
67. A computer program, comprising computer executable code, which, when executed on at least one processor, is configured to cause a first entity implementing at least a first network function for a core network of a mobile communication system to at least: receiving a digital certificate authenticating an encryption key for the first entity; wherein the digital certificate indicates one or more purposes, the digital certificate authenticating the encryption key for the one or more purposes; as well as The digital certificate is sent to a second entity, the second entity at least implementing a second network function of the core network for the mobile communication system.
68. A computer program, comprising computer executable code, which, when executed on at least one processor, is configured to cause a second entity implementing at least a second network function for a core network of a mobile communication system to at least: receiving a digital certificate from a first entity, the first entity implementing at least a first network function for the core network of the mobile communication system, the digital certificate comprising an indication of one or more purposes for which the digital certificate authenticates an encryption key for the first entity; and Based at least in part on the indication of the one or more purposes, a determination is made at the second entity whether to proceed with one or more operations involving the cryptographic key of the first entity.
69. A computer program comprising computer executable code which, when executed on at least one processor, is configured to cause an apparatus to at least: Receiving a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; and A digital certificate is issued including an indication of the one or more purposes.
70. A computer program comprising computer executable code which, when executed on at least one processor, is configured to cause an apparatus to at least: sending a request to generate a digital certificate authenticating an encryption key for a first entity, the first entity implementing one or more network functions of a core network of a mobile communication system; wherein the request indicates one or more purposes for which the digital certificate authenticates the encryption key; and A digital certificate including an indication of the one or more purposes is received.