Initial trust for network functions

By collecting information from the operating system and cloud management, and establishing trust with certificate authorities through an initial trust agent, the problem of insufficient network function certificate registration and verification in 5G/6G network environments is solved, achieving efficient and secure certificate allocation and verification, and enhancing the security and trustworthiness of network functions.

CN122073684APending Publication Date: 2026-05-22ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ALCATEL LUCENT SHANGHAI BELL CO LTD
Filing Date
2025-11-21
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

Existing network functions in 5G/6G network environments suffer from insufficient certificate registration and verification in their initial trust mechanisms, which may lead to unauthorized network functions requesting certificates. Furthermore, the lack of effective certificate management and verification mechanisms makes them difficult to adapt to cloud-native network environments.

Method used

By collecting information from the operating system, cloud management, and orchestrator, and leveraging the trust established between the initial trust agent and the certificate authority, a lightweight certificate allocation and verification mechanism is provided to ensure the authenticity and identification of network functions, suitable for cloud-native 5G/6G network environments.

Benefits of technology

It enables the efficient and secure allocation and verification of network function certificates in a cloud-native network environment, enhancing the security and trustworthiness of network functions and reducing the risk of unauthorized intrusion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122073684A_ABST
    Figure CN122073684A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to a solution for providing initial trust. In one aspect, a first device may receive a request for encrypted credentials from a second device for performing a network function. The first device may collect information about network functions. The first device may select an identification for the network function based on the collected information. The first device may obtain encrypted credentials associated with the selected identification. The first device may send encrypted credentials associated with the selected identification to a second device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various example embodiments relate to the field of communications, and more specifically to devices, methods, apparatuses, and computer-readable storage media for initial trust of network functions. Background Technology

[0002] A communication network can be viewed as a facility that enables communication between two or more communication devices, or provides communication devices with access to a data network. Mobile or wireless communication networks are an example of communication networks.

[0003] This type of communication network operates according to standards, such as those issued by 3GPP (3rd Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of such standards include the so-called 5G (fifth generation) standard or other standards issued by 3GPP. Summary of the Invention

[0004] Generally speaking, the exemplary embodiments of this disclosure provide a solution for implementing initial trust for network functions, and in particular, provide a mechanism for creating and verifying initial trust for network functions during registration.

[0005] In a first aspect, a first device is provided. The first device may include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first device to at least: receive a request for cryptographic credentials from a second device for performing network functions; collect information about the network functions; select an identifier for the network functions based on the collected information; obtain cryptographic credentials associated with the selected identifier; and send the cryptographic credentials associated with the selected identifier to the second device.

[0006] In a second aspect, a second device is provided. The second device may include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the second device to at least: send a request for cryptographic credentials to a first device; and receive cryptographic credentials associated with an identifier from the first device, wherein the identifier is selected by the first device based on information about network functions to be performed by the second device, and wherein such information is collected by the first device.

[0007] In a third aspect, a third device is provided. The third device may include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third device to at least: receive configuration information from a fourth device; and receive registration information about a network function from the fourth device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0008] In a fourth aspect, a fourth device is provided. The fourth device may include: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fourth device to at least: configure a third device using configuration information; and send registration information about a network function to the third device to register the network function to the third device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0009] In a fifth aspect, a method is provided. This method may include: receiving a request for cryptographic credentials from a second device for performing network functions; collecting information about the network functions; selecting an identifier for the network functions based on the collected information; obtaining cryptographic credentials associated with the selected identifier; and sending the cryptographic credentials associated with the selected identifier to the second device.

[0010] In a sixth aspect, a method is provided. This method may include: sending a request for an encryption credential to a first device; and receiving from the first device an encryption credential associated with an identifier, wherein the identifier is selected by the first device based on information about network functions to be performed by a second device, and wherein the information is collected by the first device.

[0011] In a seventh aspect, a method is provided. This method may include: receiving configuration information from a fourth device; and receiving registration information about a network function from the fourth device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0012] In the eighth aspect, a method is provided. This method may include: configuring a third device using configuration information; and sending registration information about a network function to the third device to register the network function with the third device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0013] In a ninth aspect, an apparatus is provided. The apparatus may include: components for receiving a request for an encryption credential from a second device for performing network functions; components for collecting information about the network functions; components for selecting an identifier for the network functions based on the collected information; components for obtaining an encryption credential associated with the selected identifier; and components for sending the encryption credential associated with the selected identifier to the second device.

[0014] In a tenth aspect, an apparatus is provided. The apparatus may include: components for sending a request for an encryption credential to a first device; and components for receiving an encryption credential associated with an identifier from the first device, wherein the identifier is selected by the first device based on information about network functions to be performed by a second device, and wherein the information is collected by the first device.

[0015] In an eleventh aspect, an apparatus is provided. The apparatus may include: components for receiving configuration information from a fourth device; and components for receiving registration information about a network function from the fourth device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0016] In a twelfth aspect, an apparatus is provided. The apparatus may include: components for configuring a third device using configuration information; and components for sending registration information about a network function to the third device to register the network function with the third device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0017] In a thirteenth aspect, a non-transitory computer-readable medium is provided, including program instructions for causing a device to perform at least any of the methods described in the fifth to eighth aspects.

[0018] In a fourteenth aspect, a computer program is provided, including instructions that, when executed by a device, cause the device to at least: receive a request for an encryption credential from a second device for performing network functions; collect information about the network functions; select an identifier for the network functions based on the collected information; obtain an encryption credential associated with the selected identifier; and send the encryption credential associated with the selected identifier to the second device.

[0019] In a fifteenth aspect, a computer program is provided, including instructions that, when executed by a device, cause the device to at least: send a request for an encryption credential to a first device; and receive an encryption credential associated with an identifier from the first device, wherein the identifier is selected by the first device based on information about network functions to be performed by a second device, and wherein the information is collected by the first device.

[0020] In a sixteenth aspect, a computer program is provided, including instructions that, when executed by a device, cause the device to at least: receive configuration information from a fourth device; and receive registration information about a network function from the fourth device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0021] In a seventeenth aspect, a computer program is provided, including instructions that, when executed by a device, cause the device to at least: configure a third device using configuration information; and send registration information about a network function to the third device to register the network function to the third device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0022] In an eighteenth aspect, a first device is provided. The first device may include: a receiving circuit system configured to receive a request for encrypted credentials from a second device for performing network functions; a collecting circuit system configured to collect information about the network functions; a selecting circuit system configured to select an identifier for the network functions based on the collected information; an obtaining circuit system configured to obtain encrypted credentials associated with the selected identifier; and a transmitting circuit system configured to transmit the encrypted credentials associated with the selected identifier to the second device.

[0023] In a nineteenth aspect, a second device is provided. The second device may include: a transmitting circuit system configured to send a request for an encryption credential to a first device; and a receiving circuit system configured to receive an encryption credential associated with an identifier from the first device, wherein the identifier is selected by the first device based on information about network functions to be performed by the second device, and wherein the information is collected by the first device.

[0024] In a twentieth aspect, a third device is provided. The third device may include: a first receiving circuit system configured to receive configuration information from a fourth device; and a second receiving circuit system configured to receive registration information about a network function from the fourth device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0025] In a twenty-first aspect, a fourth device is provided. The fourth device may include: a configuration circuit system configured to configure a third device using configuration information; and a registration circuit system configured to send registration information about a network function to the third device to register the network function with the third device, wherein the registration information includes: an identifier of the network function and attribute information of the network function.

[0026] It should be understood that the summary section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to be used to limit the scope of this disclosure. Other features of this disclosure will become apparent from the following description. Attached Figure Description

[0027] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which:

[0028] Figure 1A Examples of network architectures in which exemplary embodiments of this disclosure may be implemented are shown;

[0029] Figure 1B Examples of communication deployment architectures according to some exemplary embodiments of this disclosure are shown;

[0030] Figure 2 Example signaling procedures according to some embodiments of this disclosure are shown;

[0031] Figure 3 Example signaling procedures 300 according to some embodiments of this disclosure are shown;

[0032] Figure 4A An example signaling process for registering network functions according to an embodiment of this disclosure is shown;

[0033] Figure 4B An example signaling process for registering network functions according to another embodiment of this disclosure is shown;

[0034] Figure 4C An example signaling process for registering network functions according to another embodiment of this disclosure is shown;

[0035] Figures 5A to 5C Example signaling procedures according to some embodiments of this disclosure are shown;

[0036] Figures 6A to 6B Example signaling procedures according to some embodiments of this disclosure are shown;

[0037] Figure 7 A flowchart is shown illustrating a method implemented at a first device according to some exemplary embodiments of the present disclosure;

[0038] Figure 8 A flowchart is shown illustrating a method implemented at a second device according to some example embodiments of the present disclosure;

[0039] Figure 9 A flowchart is shown illustrating a method implemented at a third device according to some example embodiments of the present disclosure;

[0040] Figure 10A flowchart is shown illustrating a method implemented at a fourth device according to some exemplary embodiments of the present disclosure;

[0041] Figure 11 A simplified block diagram of a device suitable for implementing some example embodiments of this disclosure is shown; and

[0042] Figure 12 A block diagram illustrating an example of a computer-readable medium according to some exemplary embodiments of the present disclosure is shown.

[0043] In all the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation

[0044] The principles of this disclosure will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described for illustrative purposes only and to assist those skilled in the art in understanding and implementing this disclosure, and do not imply any limitation on the scope of this disclosure. The disclosure described herein can be implemented in various ways other than those described below.

[0045] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0046] In this disclosure, references to "an embodiment," "an embodiment," "an example embodiment," etc., indicate that the described embodiments may include specific features, structures, or characteristics, but not every embodiment necessarily includes that specific feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Additionally, when a specific feature, structure, or characteristic is described in connection with an embodiment, those skilled in the art will recognize that, whether explicitly described or not, incorporating other embodiments to affect such a feature, structure, or characteristic is within their knowledge.

[0047] It should be understood that although the terms “first” and “second”, etc., may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0048] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. As used herein, the singular forms “a,” “an,” and “the” are also intended to include the plural forms unless the context clearly indicates otherwise. It will also be understood that when the terms “comprising,” “including,” “having,” “having,” “including,” and / or “containing” are used herein, the presence of the stated features, elements, and / or components is specified, but the presence or addition of one or more other features, elements, components, and / or combinations thereof is not excluded. As used herein, “at least one of the following: ” and “at least one of ” and similar wording (where the list of two or more elements is connected by “and” or “or”) means at least any one of these elements, or at least any two or more of these elements, or at least all of these elements.

[0049] As used in this application, the term "circuit system" may refer to one or more or all of the following: (a) Hardware circuit implementation only (such as implementation only in analog and / or digital circuit systems); and (b) A combination of hardware circuitry and software, such as (if applicable): (i) A combination of (multiple) analog and / or digital hardware circuits having software / firmware, and (ii) Any part of a hardware processor(s) having software (including (multiple) digital signal processors, software, and (multiple) memories, which work together to enable a device (such as a mobile phone or server) to perform various functions; and (c) (multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or a portion thereof, which require software (e.g., firmware) to operate, but may be absent when operation is not required.

[0050] This definition of circuit system applies to all uses of the term in this application (including in any claim). As another example, as used in this application, the term circuit system also covers only hardware circuitry or a processor (or multiple processors) or portions of hardware circuitry or a processor and its accompanying software and / or firmware implementation. For example, and if applicable to a particular claim element, the term circuit system also covers baseband integrated circuits or processor integrated circuits for mobile devices, or similar integrated circuits in servers, cellular network devices or other computing or network devices.

[0051] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as Long Term Evolution (LTE), LTE-A Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. Furthermore, communication between terminal devices and network devices in the communication network can be performed according to any suitable intergenerational communication protocol, including but not limited to fourth-generation (4G), 4.5G, future fifth-generation (5G) communication protocols, future sixth-generation (6G) communication protocols, and / or any other protocols currently known or to be developed in the future. Embodiments of this disclosure can be applied to various communication systems. Due to the rapid development of communication, there will naturally be future types of communication technologies and systems that can be utilized to implement this disclosure. The scope of this disclosure should not be considered limited to the systems described above.

[0052] As used herein, the term "network device" or "network node" refers to a node in a communication network through which terminal devices access the network and receive services. A network device can refer to a system simulator, base station (BS), or access point (AP), such as a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), an NR NB (also known as a gNB), a Remote Radio Unit (RRU), a Radio Header (RH), a Remote Radio Header End (RRH), a relay, or a low-power node (such as a femtosecond, picosecond, etc.), depending on the terminology and technology used in the application.

[0053] The term "terminal device" refers to any terminal device capable of wireless communication. As an example and not a limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smartphones, Voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop devices (LMEs), USB dongles, smart devices, wireless customer premises equipment (CPEs), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in industrial and / or automated processing chain environments), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, etc. In the following description, the terms "terminal equipment", "communication equipment", "terminal", "user equipment" and "UE" are used interchangeably.

[0054] In service-based architecture (SBA) frameworks, security is a major concern because the large number of network functions communicating via open application programming interfaces (APIs) creates an increased area for potential attacks. Transport layer security (TLS) and mutual authentication play a crucial role in ensuring secure communication between these functions.

[0055] Each Network Function (NF) needs its own digital certificate, which can be used to authenticate the NF and communicate securely over an encrypted channel. The process of providing certificates can involve multiple steps. For example, the process may include a registration step for the NF. In the registration step, the device used to perform the NF first registers the NF with a Public Key Infrastructure (PKI), which issues a certificate. During registration, the device used to perform the NF may generate a key pair and a Certificate Signing Request (CSR), which is submitted to a Certificate Authority (CA).

[0056] The process may also include a certificate issuance step. During the certificate issuance step, upon receiving the CSR, the CA can verify the identity of the NF. After verification, the CA can issue a digital certificate to the device for implementing the NF, which contains its public key and other identification information.

[0057] The process may also include certificate management and renewal steps. The lifecycle of multiple certificates is managed by the CA, which is responsible for issuing, renewing, and revoking certificates as needed. During the certificate management and renewal steps, NFs can periodically renew their certificates before they expire to maintain continuous secure communication.

[0058] The process can also include a mutual authentication step. During the mutual authentication step, when two NFs need to communicate, they can exchange certificates and authenticate each other using mutual TLS (mTLS). This ensures that the two NFs are legitimate and can trust each other, significantly enhancing security.

[0059] The process may also include a secure communication step. During the secure communication step, after successful authentication, NF can use its certificate to establish an encrypted communication channel, ensuring the confidentiality and integrity of the transmitted data.

[0060] In 5G SBA, the provisioning and management of digital certificates are crucial for ensuring the security, privacy, and trustworthiness of interactions across the network. As 5G networks continue to develop and evolve, SBA's robust certificate-based authentication mechanism will be essential in defending against increasingly sophisticated cybersecurity threats.

[0061] Several solutions have been proposed. For example, the Secure Production Identification Framework for All (SPIFFE) introduces a framework for issuing SPIFFE Verifiable Identifier Documents (SVIDs) to workloads on the same node by an agent within that node. The SVID includes cryptographic attributes that allow it to be proven authentic and belonging to the workload. The framework defines APIs on the agent side to allow workloads to retrieve their SVIDs in specific environments, which may differ from cloud-based 5G / 6G deployment environments. However, the framework does not specify how to construct verifiable identifiers, how to register workloads, how to assign verifiable identifiers to workloads, how to collect and verify workload information in different environments, etc.

[0062] Another solution in 3GPP TR 33.876 establishes initial trust between the NF and the "public CA" by utilizing an initial NF certificate signed by a "private CA" in the same trust domain as the NF. For example, the NF vendor can install the initial certificate in the gNB during the post-build / pre-delivery phase. When the gNB requests a certificate from the operator CA, it can include the initial certificate in the request, and the operator CA / RA can authenticate the gNB using the vendor's root certificate pre-configured in the CA.

[0063] Another solution in 3GPP TR 33.876 utilizes remote authentication to prove the NF and, after successful authentication, requests credentials for the NF from the CA / RA. The device used to perform the NF can then use these credentials to request a certificate from the CA / RA to prove the NF's authenticity. This solution requires the NF to support authentication and sends an "extended" CSR to the CA / RA for the certificate.

[0064] When a new NF is deployed and obtains its certificate, if the information provided by the NF is not verified during CSR, it may allow a compromised NF to request a certificate containing information that does not belong to it, such as NF type and NF instance ID. Furthermore, there is no mechanism in the device used to perform Network Repository Functions (NRF) to verify the profiles registered by the NF. Some 3GPP solutions address the initial trust issue, but these solutions either require an attached CA or rely on new capabilities, such as supporting proofs, which may be difficult to adapt to cloud-native 5G / 6G network environments.

[0065] The solution disclosed herein leverages initial trust (IT) established between the IT agent and the NF based on information collected from the OS, cloud management, and orchestrator or management and maintenance (OAM) to allow credentials to be securely and efficiently distributed to the NF. Trust between the IT agent and the CA server can be established using existing technologies, such as authentication that does not require support from each NF in the node.

[0066] Figure 1A Examples of communication environments 100 in which some exemplary embodiments of this disclosure may be implemented are shown. Communication environment 100 may be part of a communication network, including one or more network devices 122, 124, and 131, one or more terminal devices 152, 154, and a core network 110. Wireless communication system 100 may support various wireless access technologies.

[0067] Network devices and terminal devices can communicate via a communication link, which can be a wireless or wired connection. For example, network devices and terminal devices can perform wireless communication (e.g., receiving signaling, sending signaling) through a Uu interface. In communication environment 100, the link from the network device to the terminal device is called a downlink (DL), and the link from the terminal device to the network device is called an uplink (UL). In the downlink, the network device is a transmitting (TX) device (or transmitter), and the terminal device is a receiving (RX) device (or receiver). In the uplink, the terminal device is a transmitting TX device (or transmitter), and the network device is an RX device (or receiver). It should be understood that the network device can provide one or more serving cells. In some embodiments, the network device can provide multiple cells.

[0068] Network devices can provide a geographic coverage area, for which they can support services (e.g., voice, video, packet data, message transmission, broadcasting, etc.) for one or more terminal devices within that coverage area. For example, network devices 122, 124, and 131, and terminal devices 152 and 154 can support wireless communication of signals associated with services (e.g., voice, video, packet data, message transmission, broadcasting, etc.) based on one or more wireless access technologies. In some embodiments, different geographic coverage areas 120 and 130 associated with the same or different wireless access technologies may overlap, but different geographic coverage areas may be associated with different network devices. In some embodiments, one or more terminal devices 152 and 154 may be distributed throughout the geographic area of ​​the wireless communication system 100.

[0069] In some embodiments, the network device may support communication with the core network 110. For example... Figure 1A As shown, core network 110 may include multiple devices 111 to 117. For example, device 111 may include an Initial Trust (IT) agent. Device 112 may be used to perform network functions. Device 113 may include a Certificate Authority (CA) server. Device 114 may include an Operations, Administration and Maintenance (OAM) device. Device 115 may include a device for performing Network Repository Functions (NRF). Device 116 may include a cluster manager, and device 117 may include an image repository device. Those skilled in the art will understand that communication links may be included between devices 111 to 117, and for clarity, these communication links are... Figure 1A The middle part is omitted.

[0070] It should be understood that although devices 111 to 117 are shown as separate devices, one or more of these devices can be implemented in the same device. Furthermore, although in Figure 1A In this context, OAM device 114 is shown as being deployed in core network 110, but OAM device 114 can also be deployed outside of core network device 110.

[0071] It should be understood that, such as Figure 1A The specific numbers of various communication devices and communication links shown are for illustrative purposes only and do not imply any limitation. Communication environment 100 may include any suitable number of communication devices, any suitable number of communication links, and any suitable number of other elements for implementing communication. Furthermore, it should be understood that various wireless and wired communications (if necessary) may exist between all communication devices.

[0072] Communication between devices in communication environment 100 can be implemented according to any suitable communication protocol(s), including but not limited to cellular communication protocols such as third-generation (3G), fourth-generation (4G), fifth-generation (5G), and sixth-generation (6G), wireless local area network communication protocols such as IEEE 802.11, and / or any other protocol currently known or to be developed in the future. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple Access (OFDM), Discrete Fourier Transform Extended OFDM (DFT-s-OFDM), and / or any other technology currently known or to be developed in the future.

[0073] Figure 1B An example of a communication deployment architecture 100' according to some exemplary embodiments of the present disclosure is shown. Architecture 100' includes a central unit (CU) 150, a core network 160, and an OAM 114. Multiple network functions can be deployed in the CU 150 and the core network 160. These network functions can be deployed in different clusters, and multiple nodes (virtual machines (VMs) or even physical servers) can be deployed in the clusters. An initial trust agent is installed and configured on each of the nodes and VMs where the multiple network functions can be deployed.

[0074] CA server 154 is located in CU 150, and CA server 164 is located in core network 160. CA server 154 or 164 can be deployed in each cluster. CA servers can also be deployed globally as OAM.

[0075] In some embodiments, OAM-related information can be exchanged between different communication entities. For example, OAM-related information can be exchanged between the IT agent and the Kubernetes orchestrator agent in each VM. OAM-related information can be exchanged between each Kubernetes orchestrator agent and the Kubernetes control plane used for CU 150. OAM-related information can be exchanged between the Kubernetes control plane and OAM. OAM-related information can be exchanged between CA server 154 or 164 and OAM 114. OAM-related information can be exchanged between the OS in CU 150 and OAM 114. OAM-related information can be exchanged between the IT agent and the OS in the node.

[0076] In some embodiments, certificate-related information can be exchanged between communicating entities. For example, certificate-related information can be exchanged between the IT agent and the CA server in CU 150, enabling the IT agent to retrieve certificates for all NFs of the node. In core network 160, certificate-related information can be exchanged between the IT agent and the CA server. Certificate-related information can also be exchanged between (multiple) NFs and the IT agent, enabling NFs to retrieve their certificates from the IT agent.

[0077] Figure 2 An example signaling process 200 according to some embodiments of the present disclosure is illustrated. Process 200 may involve a first device 111, a second device 112, a third device 113, and a fourth device 114. It should be understood that this process can also be applied to other communication scenarios. Furthermore, in signaling process 200, it is possible to add, omit, modify one or more operations, or these operations may be performed in any suitable order, without departing from the scope of the present disclosure.

[0078] In process 200, the second device 112 may send (211) a request for encryption credentials to the first device. In some embodiments, the second device is configured to perform network functions. In some embodiments, the encryption credentials may include a certificate, and therefore, the request for encryption credentials may include a Certificate Signaling Request (CSR). In some embodiments, the encryption credentials may include a token. The first device may obtain a certificate or a token based on the request for encryption credentials.

[0079] The first device 111 may collect (212) information about network functions. In some embodiments, the first device may collect information about network functions from the operating system (OS) or cluster manager 116 based on the operation of registering network functions, which is performed by the fourth device. A more detailed description of the collection of information from the OS or cluster manager 116 is described in detail below with reference to the accompanying drawings.

[0080] In some embodiments, the information collected by the first device 111 may depend on the operations performed by the fourth device 114 for registering the network function. Specifically, the information collected by the first device 111 may include a hash of the network function's image, a hash of the network function's configuration file, a unique identifier of the network function, or any combination thereof. In some embodiments, the identifier of the network function may be, for example, a process ID, which is a unique identifier in the OS for a process running on the network function.

[0081] Despite Figure 2In this disclosure, the collection step 212 follows the sending step 211; however, it should be understood that the collection step 212 may occur before the sending step 211, and this disclosure does not limit the order of these steps. In other words, the operations may be performed in any suitable order without departing from the scope of this disclosure.

[0082] The first device 111 may select (213) identifiers for network functions based on the collected information. In some embodiments, the first device 111 may select identifiers from a list. In some embodiments, the list is sent (204) by the third device 113. The list may include a list of identifiers, and the identifiers in the list are associated with multiple network functions respectively. In some embodiments, the list may include identifiers associated with multiple network functions, and may also include identifiers of these network functions. In some embodiments, these network functions are registered to the third device 113 by the fourth device 114, which will be described in detail below. The first device 111 may select (213) identifiers for network functions from the list of identifiers based on the collected information.

[0083] First device 111 can obtain (214) an encryption credential associated with the selected identifier. In some embodiments, the encryption credential may include a certificate, and therefore, a request for the encryption credential may include a Certificate Signaling Request (CSR). In some embodiments, first device 111 may send the selected identifier and CSR to third device 113 to request a certificate, and third device 113 may return a signed certificate associated with the selected identifier to first device 111, and therefore, first device 111 may receive the signed certificate associated with the selected identifier. Alternatively, first device 111 may obtain the certificate associated with the selected identifier from a plurality of certificates (e.g., a batch of certificates) that have already been received from third device 113. First device 111 may receive or download the plurality of certificates in advance from third device 113, and upon receiving a request for the encryption credential from second device 112, first device 111 may obtain the certificate associated with the selected identifier from the received plurality of certificates.

[0084] In some embodiments, the cryptographic credential may include a token. Therefore, the first device 111 may generate a token that includes an identifier of a network function (e.g., an NF ID) and attribute information of the network function. In some embodiments, the attribute information of the network function may include the type of the network function (NF Type), an identifier of the network function slide (e.g., an NF slide ID), or any combination thereof. Alternatively, a request for the cryptographic credential sent by the second device 112 may include a public key, and the first device 111 may generate the token based on that public key. The token generated by the first device 111 may include an identifier of the network function (e.g., an NF ID) and attribute information of the network function, and the attribute information of the network function may include the type of the network function (NF Type), an identifier of the network function slide (e.g., an NF slide ID), or any combination thereof.

[0085] In some embodiments, the first device 111 may send a cryptographic credential associated with a selected identifier to the second device 112. Specifically, the first device 111 may send a signing certificate associated with the selected identifier to the second device 112. In some embodiments, the certificate may include an identifier of a network function (e.g., an NF ID). In some embodiments, the certificate returned to the NF may be further enhanced to include a hash of the NF's profile as a new field. For example, the certificate returned to the NF may include an identifier of the network function (e.g., an NF ID) and a hash of the NF's profile. In some embodiments, the first device 111 may send a signing certificate obtained from a third device 113, or a token signed by the first device 111 itself, along with the certificate chain of the third device 113, to the second device 112. Alternatively, the first device 111 may send the token to the second device 112.

[0086] In some embodiments, the second device 112 may determine whether a network function profile is owned by the network function. Based on the determination that the network function profile is missing in the network function, the second device 112 may send (221) a request for the network function profile to the OAM device 114 along with encrypted credentials for the OAM device 114. The OAM device 114 may select a signed version of the network function profile based on the encrypted credentials and send (223) the signed version of the network function profile to the second device 112.

[0087] In some embodiments, the second device 112 can submit a signed version of the network function configuration file and cryptographic credentials to device 115 ( Figure 2(Not shown) Register for performing Network Repository Functions (NRF). In some embodiments, OAM device 114 can register for performing NRF by submitting a signed version of a certificate to device 115.

[0088] In some embodiments, the first device 111 may send a (202) subscription request to the third device 113 to request network function registration. In some embodiments, the subscription request may include the certificate of the node where the first device 111 is deployed. In some embodiments, the first device 111 may send the subscription request to the third device 113 before receiving a request for cryptographic credentials from the second device 112. In other words, the first device 111 may receive cryptographic credentials from the second device 112 after the second device 112 has already subscribed to the third device 113 by sending a subscription request.

[0089] In some embodiments, the first device 111 and the second device 112 reside together in a node or a virtual machine (VM). In some embodiments, the first device 111 may include an Initial Trust (IT) agent. In some embodiments, in a deployment scenario where an SCP is deployed on each node of the cluster, the functionality of the IT agent may be performed by the Service Control Point (SCP). In some embodiments, the fourth device 114 may include an Operations, Administration, and Maintenance (OAM) device. In some embodiments, the third device 113 may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF). In other words, a device for performing NRF can be adapted to act as a CA server.

[0090] Advantageously, embodiments of this disclosure provide a "lighter" way to prove the authenticity of a network function and / or the identifier of a network function (NF ID), a method that can be easily applied to cloud-native 5G / 6G network environments.

[0091] Figure 3 An example signaling process 300 according to some embodiments of the present disclosure is illustrated. Process 300 may include a first device 111, a second device 112, a third device 113, and a fourth device 114. It should be understood that this process flow can also be applied to various communication scenarios. Furthermore, in signaling process 300, it is possible to add, omit, modify one or more operations, or these operations may be performed in any suitable order, without departing from the scope of the present disclosure.

[0092] In signaling procedure 300, a fourth device 114 (e.g., an OAM device) may send (310) configuration information to a third device 113 for configuring the third device 113. The fourth device 114 may also send (320) registration information about a network function to the third device 113. In some embodiments, the registration information may include: an identifier for the network function, and attribute information about the network function. In some embodiments, the identifier for the network function may include the ID of the network function (e.g., an NF ID). In some embodiments, the attribute information about the network function may depend on the operation performed by the OAM device 114 to register the network function. For example, the attribute information about the network function may include: an image of the network function, a hash of the network function's configuration file, a unique identifier for the network function (e.g., a process ID, which is a unique identifier within the OS for a process running on the network function), or any combination thereof.

[0093] In some embodiments, the third device 113 may generate a list of identifiers. These identifiers are associated with multiple registered network functions. At 320, the network function is registered by the OAM device. In some embodiments, the list may also include an identifier for the network function. For example, at 320, the identifier for the network function may include attribute information received by the third device 113. At 204, the third device 113 sends the list of identifiers to the first device (e.g., an initial trust broker). At 211, the second device 112 may send a request for cryptographic credentials to the first device 111. At 212, in some embodiments, the first device 111 collects information about the network function. At 213, the first device 111 may select an identifier for the network function based on the information collected from the list of identifiers.

[0094] like Figure 3 In the signaling procedure 300 shown, operations 211, 212, 213, 214, 215, and 221 have been referenced. Figure 2 It is described in detail. Therefore, for the sake of clarity and conciseness, repeated descriptions are omitted in this article.

[0095] Now, a detailed description of the operations performed by the fourth device 114 for registering network functions will refer to... Figures 4A to 4C Described.

[0096] Figure 4A An example signaling process 400A for registering network functions according to an embodiment of the present disclosure is shown.

[0097] In one embodiment, at 401, a fourth device (e.g., an OAM device) 114 may first retrieve a basic image of the network function to be registered. At 402, the OAM device 114 may generate an updated image by adding a layer of a configuration file containing the network function. In some embodiments, the OAM device 114 may generate an updated image by adding a version of the configuration file's signature. At 403, the OAM device 114 may upload the updated image to an image repository device 115. In some embodiments, the OAM device may upload the updated image along with its signature to the image repository device 115. In some embodiments, the OAM device 114 may store the updated image along with metadata of the network function, and this metadata may include: an identifier for the network function, a network function identity, a sliding identifier, or any combination thereof. At 404, the OAM device 114 may send registration information about the network function to a third device 113 to register the network function with the third device 113. In some embodiments, this registration information may include an identifier for the network function (e.g., an NF ID) and attribute information of the network function. In some embodiments, the attribute information of the network function may include a hash of the image. For example, OAM device 114 can send an NF ID to third device 113, and can attach a hash of the image as an identifier to be used to properly identify the network function in order to register the network function with third device 113. In some embodiments, the attribute information of the network function may also include information on the required security trust.

[0098] Figure 4B An example signaling procedure 400B for registering a network function according to another embodiment of this disclosure is illustrated. At 421 and 422, a fourth device 114 can deploy a new network function via a cluster manager 116. In some embodiments, a second device 112 can be configured to execute the newly deployed network function. At 423, the second device 111 can send a response to the cluster manager 116. In some embodiments, the response may include first information about the node where the network function is deployed and second information about the network function. In some embodiments, the first information may include an identifier of the node where the network function is deployed, such as a node / virtual machine (VM) ID. The second information may include a unique identifier for the network function. For example, the unique identifier for the network function may include a process ID, which is a unique identifier within the OS for a process running on the network function.

[0099] At 424, cluster manager 115 can receive the response and send it to OAM device 114. At 425, OAM device 114 can assign an identifier to the network function. OAM device 114 can send registration information about the network function to third device 113 to register the network function. In some embodiments, the registration information may include one or more of the following: an identifier for the network function (e.g., NF ID), an identifier of the VM or node on which the newly deployed network function is deployed, or a unique identifier for the newly deployed network function, such as a process ID, which is a unique identifier within the OS for a process running on the network function.

[0100] At 427, the third device 113 can select a first device corresponding to the identifier of the node where the network function is deployed. In some embodiments, the first device has already subscribed to the third device 113 by sending a subscription request. At 428, the third device 113 can then send to the first device 111 a list including multiple identifiers (e.g., NF IDs) associated with multiple network functions, respectively. In some embodiments, the list may include identifiers associated with multiple network functions, and may also include identifiers of the network functions. In some embodiments, the third device 113 can send multiple certificates (e.g., a batch of certificates) to the selected first device 111. In this case, either the first device 111 or the third device 113 can generate key pairs for the certificates.

[0101] Figure 4C Another example signaling process 400C for registering network functions according to an embodiment of the present disclosure is shown.

[0102] like Figure 4C As shown, the fourth device 114 can send registration information about a network function to the third device 113 to register the network function with the third device 113. In some embodiments, the registration information may include: an identifier of the network function (e.g., NF ID) and attribute information of the network function. In some embodiments, the attribute information of the network function may include a hash of the network function's configuration file. In some embodiments, the attribute information of the network function may also include information on required security trusts.

[0103] In some embodiments, the first device 111 and the second device 112 reside together in a node or a virtual machine. In some embodiments, the first device 111 may include an Initial Trust (IT) agent. In some embodiments, in a deployment scenario where an SCP is deployed on each node of a cluster, the functionality of the IT agent may be performed by the Service Control Point (SCP). In some embodiments, the fourth device 114 may include an Operations, Administration, and Maintenance (OAM) device. In some embodiments, the third device 113 may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF). In other words, a device for performing NRF can be adapted to act as a CA server.

[0104] Figures 5A to 5C An example signaling process 500 according to some embodiments of this disclosure is shown. Process 500 may involve an initial trust (IT) agent 111, a second device 112 for performing network functions newly deployed by OAM device 114, a CA server 113, OAM device 114, a device 115 for performing NRF, a cluster manager 116, and an image repository device 117.

[0105] It should be understood that this process flow can also be applied to various communication scenarios. Furthermore, in the signaling process 500, it is possible to add, omit, or modify one or more operations without departing from the scope of this disclosure, or these operations may be performed in any suitable order.

[0106] Process 500 may include pre-configured sub-process 510. For example... Figure 5A As shown, during the pre-configured sub-process, at 511, OAM device 114 can start and configure CA server 113 in the cluster. At 512, OAM device 114 can start and configure NRF. At 513, IT agent 111 can start along with the VM during VM startup. In some embodiments, IT agent 111 is deployed within the VM. At 514, IT agent 111 can collect information about the nodes in which it is deployed. Alternatively, at 514, IT agent 111 can use a pre-shared secret to obtain node information.

[0107] At 515, the IT agent can send authentication information to CA server 113. At 516, CA server 113 can retrieve "evidence" (e.g., authentication information) from Kubernetes. Specifically, CA server 113 can send a request to OAM device 114 to retrieve the "evidence" from Kubernetes. OAM device 114 can then send the "evidence" to CA server 113. At 517, CA server 113 can verify the received information. At 518, CA server 113 can send the node / VM certificate to the client, such as IT agent 111. At 519, IT agent 111 can subscribe to NF registration by sending a subscription request to CA server 113 to request NF registration. In some embodiments, IT agent 111 can also send the node's certificate along with the subscription request to CA server 113 to request NF registration. The operation at 519 allows IT agent 111 to transmit to CA server 113, which can be used to provide identification for network functions.

[0108] Process 500 may include a sub-process of registering network functions with CA server 113. Several solutions exist for registering network functions. For example... Figures 5A to 5C As shown, the three options are represented as Option A, Option B, and Option C, respectively, which correspond to Figures 4A to 4C The embodiment shown.

[0109] Alternate option A 520 corresponds to Figure 4A The embodiment shown illustrates a solution for registering network functions to CA server 113. Figure 5A As shown, at 521, OAM device 114 can retrieve a base image of the network function (e.g., AMF) it is intended to deploy, and create a new image (also referred to as an updated image) by adding a layer of a configuration file containing that network function. In some embodiments, OAM device 114 can generate a new image by adding a signed version of the configuration file of the network function.

[0110] At 522, OAM device 114 can upload a new image to image repository device 117. In some embodiments, OAM device 114 can upload the new image along with its signature to image repository device 117. In some embodiments, OAM device 114 can store the image along with metadata for a network function, for which the image is generated, and the metadata may include one or more of an identifier for an NF instance or a sliding identifier, etc.

[0111] OAM device 114 can register a new network function identifier with CA server 113. OAM device 114 can also append a hash of an image as an identifier to be used from the agent to correctly identify the network function. In some embodiments, OAM device 114 can register a new network function by sending the network function identifier and the image hash to CA server 113. In some embodiments, OAM device 114 can also send required security trust information. In some embodiments, the network function identifier may include an NF ID.

[0112] Alternative B 530 corresponds to Figure 4B The embodiment shown illustrates another solution for registering network functionality with CA server 113. Figure 5B As shown, at points 531 and 532, OAM device 114 can deploy new network functions via cluster manager 116. At point 533, cluster manager 116 can collect information from the nodes where the new network function is deployed. Specifically, cluster manager 116 can collect the unique identifiers of the nodes (i.e., node ID / virtual machine ID) and the unique identifiers of the network functions (i.e., process IDs). At point 534, cluster manager 116 can send the collected information to OAM device 114.

[0113] At 535, OAM device 114 can assign a new identifier (e.g., NF ID) to a new network function. At 536, OAM device 114 can register a new NF / NF service instance with CA server 113. For example, OAM device 114 can register a new NF identifier with CA server 113, appending identifier information (i.e., node ID and NF ID) received during NF deployment to be used by the agent to correctly identify the NF. In some embodiments, OAM device 114 can register a new network function with CA server 113 by sending the network function's identifier, and one or more of the following: a unique identifier for the node (i.e., node ID / virtual machine ID), or a unique identifier for the network function (i.e., process ID).

[0114] At 537, CA server 113 can select the IT agent corresponding to the node ID. In other words, CA server 113 can select the IT agent on the correct node. CA server 113 can push new identification information to the selected agent. In some embodiments, CA server 113 can send to IT agent 111 a list including multiple identifiers associated with multiple network functions, for example, as shown at 551. In some embodiments, the list may include identifiers associated with multiple network functions, and may also include identifiers of the network functions. In some embodiments, CA server 113 can send multiple certificates (e.g., a batch of certificates) to the selected IT agent 111. In this case, either IT agent 111 or CA server 113 can generate key pairs for the certificates.

[0115] like Figure 5B As shown, alternative C 540 corresponds to Figure 4C The embodiment shown illustrates another solution for registering network functionality with CA server 113. Figure 5B As shown, at 541, OAM device 114 can register a new identifier (e.g., NF identifier or NF ID) for a network function with CA server 113. OAM device 114 can also append a hash of the network function's profile as an identifier to be used from the agent to correctly identify the network function. In some embodiments, OAM device 114 can register a new network function with CA server 113 by sending the network function's identifier and the hash of its profile to CA server 113. In some embodiments, OAM device 114 can also send required security trust information. In some embodiments, the identifier of the network function may include an NF ID.

[0116] In some embodiments, for example at 551, CA server 113 may forward a list of NF IDs and identifiers(s) to the corresponding agent. Those skilled in the art will understand that operation 551 and subsequent operations may follow operations of alternative A, alternative B, or alternative C. In other words, after OAM device 114 registers the NF with CA server 113 at 523, 536, and 541, CA server 113 may send a list of workload identifiers to IT agent 111. In some embodiments, the agent may include all possible nodes in which the new NF can run. Alternate B is the only agent in which there will always be only one.

[0117] At points 552 and 553, OAM device 114 can deploy new network functions via a cloud manager (e.g., cluster manager 116). For alternatives A and C, operations 552 and 553 can be performed; while for alternative B, operations 552 and 553 can be omitted because the deployment has already been performed at points 531 and 532.

[0118] At 554, the newly deployed network function is activated. At 555, the second device 112, used to execute the newly deployed network function, can send a request for a certificate or token through a new interface. At 556, the IT agent 111 can collect information about the network function from the underlying OS or from a cloud manager (e.g., the Kubernetes control plane or kubelet) to retrieve the necessary information. Specifically, each alternative (e.g., alternative A, B, or C) may require a corresponding agent to retrieve different information already provided by the OAM device 114. For alternatives A and B, the IT agent 111 can collect information from the OS associated with the IT agent and the network function. For alternative C, the IT agent 111 can collect information from the cluster manager 116. For alternative A, the collected information may include a hash of the network function's image. For alternative B, the collected information may include a process ID for the network function. In some embodiments, for alternative C, the IT agent 111 can collect information from the cluster manager 116, and in Kubernetes, the collected information may correspond to configuration mapping content.

[0119] Despite Figure 5B In this disclosure, the collection step 556 follows the sending step 555; however, it should be understood that the collection step 556 may occur before the sending step 555, and this disclosure does not limit the order of these steps. In other words, the operations may be performed in any suitable order without departing from the scope of this disclosure.

[0120] At 557, after retrieving the required information, IT agent 111 can select the corresponding NF ID. In some embodiments, IT agent 111 can select the correct identifier based on information provided by OAM device 114 and information collected by IT agent 111. In some embodiments, at 555, based on the determination that the request from second device 112 includes a request for authentication (e.g., CSR), IT agent 111 can further complete the CSR, and IT agent 111 can send the NFID and CSR to CA server 113, for example, at 558. CA server 113 can return a signed certificate. At 559, IT agent 111 can send the received certificate to second device 112. Alternatively, IT agent 111 can obtain a certificate associated with the selected NF ID from multiple certificates (e.g., a batch of certificates), which are received from CA server 113. IT agent 111 may receive or download the multiple certificates in advance from CA server 113, and upon receiving a request for cryptographic credentials, IT agent 111 may retrieve the certificate associated with the selected NF ID from the received multiple certificates. In some embodiments, the certificate may include an identifier of a network function (e.g., an NF ID). In some embodiments, the certificate returned to the NF may be further enhanced to include a hash of the NF's configuration file as a new field.

[0121] Alternatively, at 555, based on the determination that the request from the second device 112 includes a request for a token, the IT agent 111 can create a corresponding token that includes network function attributes of the network function instance, such as NF ID, NF type, NF sliding ID, etc. Figure 5C As shown, at 559, IT agent 111 can send the created token to second device 112.

[0122] like Figure 5C As shown, in some embodiments, IT agent 111 may send a signed certificate obtained from CA server 113, or a token signed by IT agent 111 itself, together with the certificate chain of CA server 113, to second device 112. The operations performed at 555 to 559 may be similar to those at 211 to 215, and for the sake of clarity and brevity, repeated descriptions are omitted herein.

[0123] If a network function does not possess a configuration file (as shown at 560), it can use a retrieved certificate or token to authenticate with OAM device 114 and request a signed configuration file. In some embodiments, second device 112 can request a configuration file by authenticating with OAM device 114. For example, at 561, the second device can send a request for a configuration file to the OAM device along with the certificate or token received at 559. At 562, OAM device 114 can select the correct configuration file for the network function based on authentication information (e.g., based on the received certificate) and return a signed version of the network function's configuration file to second device 112. The operations performed at 561 and 562 can be similar to those at 221 and 223, and for clarity and brevity, repeated descriptions are omitted herein.

[0124] In some embodiments, a network function or OAM device 114 may register a new network function with the NRF by submitting a signed version of a certificate to the NRF, as shown at 563 and 564, respectively. For example, at 563, a second device 112 may register a new network function with the NRF by submitting a signed configuration file and / or a certificate (or token). Alternatively, at 564, OAM device 114 may register a new network function with the NRF by submitting a signed configuration file.

[0125] Figures 6A to 6B Another example signaling process 600 according to some embodiments of this disclosure is illustrated. Process 600 may involve an initial trust (IT) agent 111, a second device 112 for performing network functions newly deployed by OAM device 114, OAM device 114, a device 115 for performing NRF, a cluster manager 116, and an image repository device 117. In some embodiments, device 115 for performing NRF is already adapted to act as a CA server. It is also conceivable that, in this variant, device 115 for performing NRF acts as a CA server and exposes new services to interact with OAM device 114 and IT agent 111 to enable NF authentication.

[0126] It should be understood that this process flow can also be applied to various communication scenarios. Furthermore, within the signaling process 600, it is possible to add, omit, or modify one or more operations without departing from the scope of this disclosure, or these operations may be performed in any suitable order.

[0127] exist Figures 6A to 6BIn this context, IT Agent 111 is envisioned as co-located with the network function and responsible for verifying and certifying the NF image / attributes. In cases where the SCP co-located with the network function but is not a central SCP, the function can also be envisioned as part of the SCP; or it can be considered as part of a new network entity responsible for verifying the network function.

[0128] Process 600 may include a sub-process 610 for IT agent registration. The IT agent registration sub-process 610 is similar to... Figure 5A The pre-configured sub-process 510 is shown below. Figure 6A As shown, during subprocess 610, at 611, OAM device 114 can configure NRF, for example, by utilizing trust domain information (e.g., certificates, etc.). At 612, IT agent 111 can retrieve information about the machine in which it operates, and / or use a pre-shared key (i.e., authentication information).

[0129] At 613, IT agent 111 can send a request (e.g., nNRF_AgentInitiation) to the NRF to initiate agent registration. In some embodiments, the IT agent can send this request along with authentication information and a CSR to device 115 for NRF enforcement.

[0130] At 614, device 115 for performing NRF can send a request to OAM device 114 to request verification. In some embodiments, at 613, the request may include authentication information received from IT agent 111. At 615, OAM device 114 can verify the received information. If verification is successful, OAM device 114 can store the verified agent information. At 616, OAM device 114 can send the verification result to device 115.

[0131] At 617, the device 115 for implementing the NRF then generates a node certificate for IT agent 111 and configures IT agent 111 using the generated certificate. At 618, IT agent 111 can send a subscription request to the NRF to request network function registration. This allows IT agent 111 to transmit to the NRF that the NRF can be used to provide an identifier for the network function.

[0132] Process 600 may include sub-processes for creating managed object instances. These sub-processes for creating managed object instances are similar to... Figures 5A to 5C The sub-process for registering network functionality is shown below. Similarly, the sub-process for creating managed object instances may also include... Figures 5A to 5B The options A, B, and C are shown in the diagram.

[0133] There are multiple solutions for registering network functions. For example... Figures 6A to 6BAs shown, the three options are represented as Option A, Option B, and Option C, respectively, which correspond to Figures 4A to 4C The embodiment shown.

[0134] Alternative A 620 corresponds to Alternative A 520 and illustrates a solution for registering network functions with device 114. For example... Figure 6A As shown, at 621, OAM device 114 can retrieve a basic image of the network function (e.g., AMF) it intends to deploy and create a new image (also referred to as the updated image) by adding a layer of a configuration file (e.g., an NF configuration file) containing the network function. In some embodiments, the NF configuration file may include specific attributes of the network function. In some embodiments, OAM device 114 can generate a new image by adding a signed version of the configuration file for the network function.

[0135] At 622, OAM device 114 can upload a new image to image repository device 117. Image repository device 117 is envisioned at the Analytics Data Repository Function (ADRF). In some embodiments, OAM device 114 can upload a new image along with a signature of the new image to image repository device 117. In some embodiments, OAM device 114 can store the image along with metadata for a network function, for which the image is generated, the metadata including one or more of an identifier of an NF instance or a sliding identifier, etc.

[0136] At 623, a network function (or network function service instance) is registered by OAM device 114 to the NRF (i.e., CA server 113), including an NF ID, such as a hash of the generated image, etc. OAM device 114 can register a new network function identifier with the NRF. OAM device 114 can also append the image hash as an identifier to be used from the agent to correctly identify the network function. In some embodiments, OAM device 114 can register a new network function with the NRF by sending the network function identifier and the image hash to CA server 113. In some embodiments, OAM device 114 can also send the required security trust information. In some embodiments, the network function identifier may include an NF ID.

[0137] For subroutines 630 and 640, the corresponding operations 631 to 637 and 642 can be understood by referring to the descriptions of subroutines 530 and 540, respectively. For the sake of clarity and conciseness, repeated descriptions are omitted in this document.

[0138] Process 600 may include the subprocess 650 for NF deployment. For example... Figure 6BAs shown, subprocess 650 is similar to the set of operations 551 to 563. For clarity and brevity, repeated descriptions are omitted herein. At 651, device 115 may send a list of workload identifiers to IT agent 111. In some embodiments, this list may include multiple identifiers associated with multiple network functions, respectively. In some embodiments, the list may include identifiers associated with multiple network functions, and may also include identifiers of network functions. The operation at 651 is similar to the operation at 551, and repeated descriptions are omitted herein.

[0139] The operations of deploying new network functions at 652 by OAM device 114 and deploying new images at 653 correspond to... Figure 5B Operations 552 and 553 in the above are relevant. For Alternative B, since operations 631 and 632 have already been implemented to deploy the network function, the operations of deploying the new network function at 652 by OAM device 114 and deploying the new image at 653 can be skipped. Operation 654 for activating the new network function is similar to... Figure 5B The operation of 554 in [the context]. Figure 6B In the middle, at 655, the new image is deployed at the NF, and the second device 112 used to execute the NF can request a token / certificate from the IT agent for verification.

[0140] At position 656, the IT agent 111, co-located with the NF, can collect information about the network function from the OS or from the cluster manager. For example, for option A, the IT agent 111 can collect the hash of the NF's image, which can uniquely identify the network function's configuration file. For options A and B, the IT agent 111 can collect information from the IT agent and the OS on which the network function is deployed. For option C, the IT agent 111 can collect information from the cluster manager 116. For option A, the collected information may include the hash of the network function's image. For option B, the collected information may include the process ID for the network function. In some embodiments, for option C, the IT agent 111 can collect information from the cluster manager 116, and in Kubernetes, the collected information may correspond to configuration mapping content.

[0141] Despite Figure 6B In this disclosure, the collection step 656 follows the sending step 655; however, it should be understood that the collection step 656 may occur before the sending step 655, and this disclosure does not limit the order of these steps. In other words, the operations may be performed in any suitable order without departing from the scope of this disclosure.

[0142] At 657, after retrieving the required information, IT agent 111 can select the corresponding NF ID. In some embodiments, IT agent 111 can select the correct identifier based on information provided by OAM device 114 and collected by IT agent 111. For option A, IT agent 113 can select the correct identifier based on the hash of the image. At 655, Figure 6B The request from the second device 112 is shown to be a token request; therefore, the IT agent 111 can create a corresponding token, which includes the network function attributes of the NF instance, such as the NF instance ID, NF type, NF sliding ID, etc. Then, at 658, the IT agent 111 sends the access token to the NF deployed in the second device 112.

[0143] In some embodiments, in response to a request for a certificate, IT agent 111 may complete a Certificate Request (CSR) and send the NF ID and CSR to device 115 to perform an Network Function Request (NFR) acting as a CA server. Device 115 may return a signed certificate. IT agent 111 may send the received certificate to a second device 112. Alternatively, IT agent 111 may obtain a certificate associated with a selected NF ID from a plurality of certificates (e.g., a batch of certificates) received from CA server 113. IT agent 111 may receive or download the plurality of certificates in advance from CA server 113, and upon receiving a request for cryptographic credentials, IT agent 111 may obtain the certificate associated with the selected NF ID from the plurality of received certificates. In some embodiments, the certificate may include an identifier of a network function (e.g., an NF ID). In some embodiments, the certificate returned to the NF may be further enhanced to include a hash of the NF's profile as a new field.

[0144] In some embodiments, at 660, the NF can obtain the received token and can perform registration at the NRF. Alternatively, upon successful authentication of the network function, the IT agent 111 can send a notification to the OAM device 114, and then at 659, the OAM device 114 can register the network function with the NRF on behalf of the NF.

[0145] Advantageously, embodiments of this disclosure provide a solution for how to provide initial trust to a network function as a certificate or token when the network function does not provide information about its identity.

[0146] It should be understood that the identifier of a network function can include a Uniform Resource Identifier (URI). In other words, the identifier of a network function can include an NF ID or a URI. An example of a URI could be: 3gpp: / / TRUST_DOMAIN / hash_of_profile / PLMNID / SETID / NFIstanceID. Using a URI allows for the addition of information protected by the certificate / token itself. When a URI is not used, the NF ID can contain all the necessary information for correctly compiling the certificate, namely, the NF instance ID, the NF type, and the hash of the optional network function's profile.

[0147] According to embodiments of this disclosure, the OAM is the initiator of the NF identifier and can instruct the CA (and IT agent) server regarding the mapping between NF attributes and NF identifiers. The NF can request its initial cryptographic credentials (i.e., a certificate or token), and the certificate returned to the NF can be enhanced to include the hash of the configuration file as a new field. Embodiments of this disclosure employ a new configuration file signature from the OAM to allow for further verification of all information in the NF configuration file.

[0148] Figure 7 A flowchart of a method 700 implemented at a first device according to some example embodiments of the present disclosure is shown. For discussion purposes, method 700 will be referred to Figure 1A or Figure 1B Described from the perspective of the first device 110. Furthermore, in method 700, it is possible to add, omit, modify one or more operations, or to perform these operations in any suitable order, without departing from the scope of this disclosure.

[0149] At 710, the first device can receive a request for encryption credentials from the second device used to perform network functions. At 720, the first device can collect information about the network functions. At 730, the first device can select an identifier for the network functions based on the collected information. At 740, the first device can obtain encryption credentials associated with the selected identifier. At 750, the first device can send the encryption credentials associated with the selected identifier to the second device.

[0150] In some embodiments, the encryption credential may include a certificate, and a request for the encryption credential may include a Certificate Signing Request (CSR). The first device may send a selected identifier and a CSR to a third device to request the certificate and may receive the certificate associated with the selected identifier from the third device.

[0151] In some embodiments, the encryption credential may include a certificate, and a request for the encryption credential may include a certificate signing request (CSR), and the first device may obtain a certificate associated with a selected identifier from a plurality of certificates received from a third device.

[0152] In some embodiments, the cryptographic credentials may include a token, and the first device may generate the token, which includes identification and attribute information of the network function.

[0153] In some embodiments, a request for a cryptographic credential may include a public key, and the first device may generate the token based on the public key.

[0154] In some embodiments, the first device may send a subscription request to the third device to request network function registration, and the subscription request may include: the certificate of the node where the first device is deployed.

[0155] In some embodiments, the first device may receive a list of identifiers from the third device, wherein the identifiers in the list are associated with a plurality of network functions, and the identifiers for the network functions are selected from the list.

[0156] In some embodiments, multiple network functions associated with identifiers in the list are registered by a fourth device to a third device.

[0157] In some embodiments, the first device may collect information about network functions by: collecting information about network functions from the operating system (OS) or cluster manager 116 based on the operation of registering network functions, the operation being performed by the fourth device.

[0158] In some embodiments, information about a network function may include one or more of the following: a hash of the network function's image, a hash of the network function's configuration file, or a unique identifier for the network function.

[0159] In some embodiments, the first device and the second device reside together in a node or a virtual machine.

[0160] In some embodiments, the first device may send the cryptographic credentials associated with the selected identifier to the second device by sending the cryptographic credentials associated with the selected identifier together with the certificate chain of the third device to the second device.

[0161] In some embodiments, the first device may include an initial trust (IT) agent.

[0162] In some embodiments, the third device may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF).

[0163] In some embodiments, the fourth device may include an operation, management and maintenance (OAM) device.

[0164] Figure 8 A flowchart of method 800 implemented at a second device is shown. For the purposes of discussion, method 800 will be described from the perspective of a device performing network functions. Furthermore, in method 800, it is possible to add, omit, modify one or more operations, or to perform these operations in any suitable order, without departing from the scope of this disclosure.

[0165] At point 810, the second device may send a request for encryption credentials to the first device. At point 820, the second device may receive encryption credentials associated with an identifier from the first device. In some embodiments, the identifier is selected by the first device based on information about network functions to be performed by the second device, and such information is collected by the first device.

[0166] In some embodiments, the encryption credential may include a certificate, the request for which the encryption credential includes a certificate signing request (CSR), and the certificate associated with the identifier is received by the first device from the third device.

[0167] In some embodiments, the cryptographic credential may include a token, and the token may include identification and attribute information of the network function.

[0168] In some embodiments, a request for the cryptographic credential may include a public key, and a token may be generated by a first device based on the public key.

[0169] In some embodiments, the first device and the second device reside together in a node or a virtual machine.

[0170] In some embodiments, information about a network function may include one or more of the following: a hash of the network function's image, a hash of the network function's configuration file, or a unique identifier for the network function.

[0171] In some embodiments, the second device may receive the cryptographic credentials associated with the identifier by receiving the cryptographic credentials associated with the identifier from the first device together with the certificate chain of the third device.

[0172] In some embodiments, the second device may send a request for a network function configuration file to the fourth device, along with encryption credentials, based on the determination that a network function configuration file is missing in the network function; and receive a signed version of the network function configuration file from the fourth device, and the fourth device may select a signed version of the network function configuration file based on the encryption credentials.

[0173] In some embodiments, a second device may register with the device for performing a Network Repository Function (NRF) by submitting a signed version of the network function’s configuration file and cryptographic credentials.

[0174] In some embodiments, the first device may include an initial trust (IT) agent.

[0175] In some embodiments, the third device may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF).

[0176] In some embodiments, the fourth device may include an operation, management and maintenance (OAM) device.

[0177] Figure 9 A flowchart of method 900 implemented at a third device is shown. For the purposes of discussion, method 900 will be described from the perspective of a third device acting as a CA server. Furthermore, in method 900, it is possible to add, omit, modify one or more operations, or to perform these operations in any suitable order, without departing from the scope of this disclosure.

[0178] In some embodiments, at 910, the third device can receive configuration information from the fourth device. At 920, the third device can receive registration information about a network function from the fourth device, and the registration information may include: an identifier of the network function and attribute information of the network function.

[0179] In some embodiments, attribute information may include one or more of the following: a hash of the network function's image, a hash of the network function's configuration file, or a unique identifier for the network function.

[0180] In some embodiments, the third device may select a first device corresponding to an identifier of the node where the network function is deployed, and the first device has already subscribed to the third device by sending a subscription request. The third device may send a list of identifiers to the selected first device, and the identifiers in the list are associated with multiple network functions respectively.

[0181] In some embodiments, the network function is deployed by a fourth device through a cluster manager, and the fourth device receives first information about the nodes and second information about the network function from the cluster manager, and assigns an identifier to the network function.

[0182] In some embodiments, the first information may include: the identifier of the node where the network is deployed, and the second information may include: a unique identifier for the network function.

[0183] In some embodiments, the first device may include an initial trust (IT) agent.

[0184] In some embodiments, the third device may include a Certificate Authority (CA) server separate from the device used to perform the Network Repository Function (NRF).

[0185] In some embodiments, the third device may include a CA server implemented by a device for performing NRF.

[0186] In some embodiments, the configuration information may include: trust domain information.

[0187] In some embodiments, the network functions are performed by a second device.

[0188] In some embodiments, the fourth device may include an operation, management and maintenance (OAM) device.

[0189] Figure 10 A flowchart of method 1000 implemented at a fourth device is shown. For the purposes of discussion, method 1000 will be described from the perspective of the OAM device. Furthermore, in method 1000, it is possible to add, omit, modify one or more operations, or to perform these operations in any suitable order, without departing from the scope of this disclosure.

[0190] In some embodiments, at 1010, the fourth device may configure the third device using configuration information. At 1020, the fourth device may send registration information about a network function to the third device to register the network function with the third device, and the registration information may include: an identifier of the network function and attribute information of the network function.

[0191] In some embodiments, the attribute information may include one or more of the following: a hash of the network function's image, a hash of the network function's configuration file, or a unique identifier for the network function.

[0192] In some embodiments, the fourth device may retrieve a basic image of the network functionality; generate an updated image by adding a layer of a configuration file with the network functionality; and upload the updated image to an image repository device.

[0193] In some embodiments, the fourth device may upload the updated signature of the image to the image repository device.

[0194] In some embodiments, the fourth device can generate an updated image by adding a signed version of the configuration file.

[0195] In some embodiments, the fourth device may store the updated image along with metadata of the network function, and the metadata may include at least one of the following: an identifier of the network function, or a sliding identifier.

[0196] In some embodiments, the fourth device can deploy network functions through a cluster manager; receive first information about the node where the network function is deployed, and second information about the network function; and assign an identifier to the network function.

[0197] In some embodiments, the first information may include: the identifier of the node where the network is deployed, and the second information may include: a unique identifier for the network function.

[0198] In some embodiments, the fourth device may receive a request for a network function profile from the second device for performing the network function, along with cryptographic credentials from the network function; select a version of the signature of the network function profile based on the cryptographic credentials; and send the version of the signature of the network function profile to the second device.

[0199] In some embodiments, the third device may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF).

[0200] In some embodiments, the fourth device may include an operation, management and maintenance (OAM) device.

[0201] In some exemplary embodiments, the apparatus capable of performing method 700 (e.g., the apparatus) may include components for performing the corresponding steps of method 700. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit system or a software module.

[0202] In some embodiments, the apparatus may include: components for receiving a request for an encryption credential from a second device for performing network functions. The apparatus may include: components for collecting information about the network functions. The apparatus may include: components for selecting an identifier for the network functions based on the collected information. The apparatus may include: components for obtaining an encryption credential associated with the selected identifier. The apparatus may include: components for sending the encryption credential associated with the selected identifier to the second device.

[0203] In some embodiments, the encryption credential may include a certificate, and a request for the encryption credential may include a certificate signing request (CSR). The apparatus may include components for sending a selected identifier and a CSR to a third device to request a certificate, and may include components for receiving a certificate associated with the selected identifier from the third device.

[0204] In some embodiments, the cryptographic credential may include a certificate, and a request for the cryptographic credential may include a certificate signing request (CSR), and the apparatus may include components for obtaining a certificate associated with a selected identifier from a plurality of certificates received from a third device.

[0205] In some embodiments, the cryptographic credential may include a token, and the apparatus may include components for generating the token, the token including identification and attribute information of network functions.

[0206] In some embodiments, a request for the cryptographic credential may include a public key, and the apparatus may include components for generating the token based on the public key.

[0207] In some embodiments, the apparatus may include a component for sending a subscription request to a third device to request network function registration, and the subscription request may include a certificate of the node where the first device is deployed.

[0208] In some embodiments, the apparatus may include: a component for receiving a list of identifiers from a third device, wherein the identifiers in the list are associated with a plurality of network functions, and an identifier for a network function is selected from the list.

[0209] In some embodiments, multiple network functions associated with identifiers in the list are registered by a fourth device to a third device.

[0210] In some embodiments, the component for collecting information about network functions may include: a component for collecting information about network functions from the operating system (OS) or cluster manager 116 based on the operation of registering network functions, the operation being performed by a fourth device.

[0211] In some embodiments, information about a network function may include one or more of the following: a hash of the network function's image, a hash of the network function's configuration file, or a unique identifier for the network function.

[0212] In some embodiments, the first device and the second device reside together in a node or a virtual machine.

[0213] In some embodiments, the apparatus may include a component for sending an encrypted credential associated with a selected identifier to a second device by sending the encrypted credential associated with the selected identifier together with a certificate chain of a third device to the second device.

[0214] In some embodiments, the first device may include an initial trust (IT) agent.

[0215] In some embodiments, the third device may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF).

[0216] In some embodiments, the fourth device may include an operation, management and maintenance (OAM) device.

[0217] In some embodiments, the apparatus further includes components for performing other steps in some embodiments of method 700. In some embodiments, the components include at least one processor and at least one memory, the at least one memory including computer program code, the at least one memory and the computer program code being configured together with the at least one processor to cause execution of the apparatus.

[0218] In some example embodiments, the apparatus capable of performing method 800 (e.g., the apparatus itself) may include components for performing the corresponding steps of method 800. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit system or a software module.

[0219] In some embodiments, the apparatus may include components for sending a request for an encryption credential to a first device. The second device may include components for receiving an encryption credential associated with an identifier from the first device. In some embodiments, the identifier is selected by the first device based on information about network functions to be performed by the second device, and wherein this information is collected by the first device.

[0220] In some embodiments, the encryption credential may include a certificate, the request for which the encryption credential includes a certificate signing request (CSR), and the certificate associated with the identifier is received by the first device from the third device.

[0221] In some embodiments, the cryptographic credential includes a certificate, wherein a request for the cryptographic credential includes a Certificate Signing Request (CSR), and wherein a certificate associated with the selected identifier is obtained from a plurality of certificates received from a third device.

[0222] In some embodiments, the cryptographic credential may include a token, and the token may include identification and attribute information of the network function.

[0223] In some embodiments, a request for the cryptographic credential may include a public key, and a token may be generated by a first device based on the public key.

[0224] In some embodiments, the first device and the second device reside together in a node or a virtual machine.

[0225] In some embodiments, information about a network function may include one or more of the following: a hash of the network function's image, a hash of the network function's configuration file, or a unique identifier for the network function.

[0226] In some embodiments, the apparatus may include a component for receiving cryptographic credentials associated with an identifier by receiving cryptographic credentials associated with an identifier from a certificate chain of a first device together with a third device.

[0227] In some embodiments, the apparatus may include: components for sending a request for a network function profile to a fourth device along with cryptographic credentials based on the determination that a network function profile is missing in the network function; and components for receiving a signed version of the network function profile from the fourth device, wherein the fourth device may select a signed version of the network function profile based on the cryptographic credentials.

[0228] In some embodiments, the apparatus may include a component for registering the device for performing the Network Repository Function (NRF) by submitting a signed version of the network function’s configuration file and cryptographic credentials.

[0229] In some embodiments, the first device may include an initial trust (IT) agent.

[0230] In some embodiments, the third device may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF).

[0231] In some embodiments, the fourth device may include an operation, management and maintenance (OAM) device.

[0232] In some embodiments, the apparatus further includes components for performing other steps in some embodiments of method 800. In some embodiments, the components include at least one processor and at least one memory, the at least one memory including computer program code, the at least one memory and the computer program code being configured together with the at least one processor to cause execution of the apparatus.

[0233] In some example embodiments, the apparatus capable of performing method 900 (e.g., the apparatus itself) may include components for performing the corresponding steps of method 900. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit system or a software module.

[0234] In some embodiments, the apparatus may include a component for receiving configuration information from a fourth device. The apparatus may also include a component for receiving registration information about a network function from the fourth device, and the registration information may include an identifier of the network function and attribute information of the network function.

[0235] In some embodiments, attribute information may include one or more of the following: a hash of the network function's image, a hash of the network function's configuration file, or a unique identifier for the network function.

[0236] In some embodiments, the apparatus may include: a component for selecting an identifier of a first device corresponding to the node where the network function is deployed, and the first device has subscribed to a third device by sending a subscription request. The apparatus may also include: a component for sending a list of identifiers to the selected first device, wherein the identifiers in the list are associated with multiple network functions.

[0237] In some embodiments, the network function is deployed by a fourth device through a cluster manager, and the fourth device receives first information about the nodes and second information about the network function from the cluster manager, and assigns an identifier to the network function.

[0238] In some embodiments, the first information may include: the identifier of the node where the network is deployed, and the second information may include: a unique identifier for the network function.

[0239] In some embodiments, the first device may include an initial trust (IT) agent.

[0240] In some embodiments, the third device may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF).

[0241] In some embodiments, the third device may include a CA server implemented by a device for performing NRF.

[0242] In some embodiments, the configuration information may include: trust domain information.

[0243] In some embodiments, the network functions are performed by a second device.

[0244] In some embodiments, the fourth device may include an operation, management and maintenance (OAM) device.

[0245] In some embodiments, the apparatus further includes components for performing other steps in some embodiments of method 900. In some embodiments, the components include at least one processor and at least one memory, the at least one memory including computer program code, the at least one memory and the computer program code being configured together with the at least one processor to cause execution of the apparatus.

[0246] In some example embodiments, the apparatus capable of performing method 1000 (e.g., the apparatus itself) may include components for performing the corresponding steps of method 1000. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit system or a software module.

[0247] In some embodiments, the apparatus may include components for configuring a third device using configuration information. The apparatus may also include components for sending registration information about a network function to the third device to register the network function with the third device, and the registration information may include an identifier of the network function and attribute information of the network function.

[0248] In some embodiments, the attribute information may include one or more of the following: a hash of the network function's image, a hash of the network function's configuration file, or a unique identifier for the network function.

[0249] In some embodiments, the apparatus may include: components for retrieving a basic image of the network functionality; components for generating an updated image by adding a layer of a configuration file with network functionality; and components for uploading the updated image to an image repository device.

[0250] In some embodiments, the apparatus may include components for uploading an updated signature of an image to an image repository device.

[0251] In some embodiments, the component for generating the updated image may include a component for adding a signed version of the configuration file.

[0252] In some embodiments, the apparatus may include a component for storing the updated image along with metadata of the network function, and the metadata includes at least one of the following: an identifier of the network function, or a sliding identifier.

[0253] In some embodiments, the apparatus may include: components for deploying network functions via a cluster manager; components for receiving first information about the node where the network function is deployed and second information about the network function; and components for assigning an identifier to the network function.

[0254] In some embodiments, the first information may include: the identifier of the node where the network is deployed, and the second information may include: a unique identifier for the network function.

[0255] In some embodiments, the apparatus may include: components for receiving a request for a network function profile from a second device for performing a network function, together with cryptographic credentials from the network function; components for selecting a version of the signature of the network function profile based on the cryptographic credentials; and components for sending the version of the signature of the network function profile to the second device.

[0256] In some embodiments, the third device may include a Certificate Authority (CA) server or a device for performing Network Repository Functions (NRF).

[0257] In some embodiments, the fourth device may include an operation, management and maintenance (OAM) device.

[0258] In some embodiments, the apparatus further includes components for performing additional steps in some embodiments of method 1000. In some embodiments, the components include at least one processor and at least one memory, the at least one memory including computer program code, the at least one memory and the computer program code being configured together with the at least one processor to cause execution of the apparatus.

[0259] Figure 11 A simplified block diagram of a device 1100 suitable for implementing some example embodiments of the present disclosure is shown. Device 1100 may be provided to implement, for example, Figure 1A or Figure 1B The device shown is, for example, a first device, a second device, a third device, or a fourth device. As shown, device 1100 includes one or more processors 1110, one or more memories 1120 coupled to processor 1110, and one or more communication modules 1140 coupled to processor 110.

[0260] Communication module 1140 is used for bidirectional communication. Communication module 1140 has at least one antenna to facilitate communication. The communication interface can represent any interface required for communication with other network elements.

[0261] Processor 1110 can be any type suitable for a local technology network, and by way of non-limiting example, can include one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. Device 1200 can have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock synchronized with the main processor.

[0262] Memory 1120 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1124, electrically programmable read-only memory (EPROM), flash memory, hard disk, optical disc (CD), digital video disc (DVD), and other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1122, and other volatile memories that will not persist during power outages.

[0263] Computer program 1130 includes computer-executable instructions that are executed by the associated processor 1110. Program 1130 may be stored in ROM 1124. Processor 1110 may perform any suitable actions and processes by loading program 1130 into RAM 1122.

[0264] Embodiments of this disclosure can be implemented via program 1130, enabling device 700 to execute any process of this disclosure, as referenced. Figures 1A to 10 The embodiments of this disclosure can also be implemented in hardware or by a combination of software and hardware.

[0265] In some example embodiments, program 1130 may be tangibly contained in a computer-readable medium, which may be included in device 1100 (e.g., in memory 1120) or in other storage devices accessible by device 1100. Device 1100 may load program 1130 from the computer-readable medium into RAM 1122 for execution. The computer-readable medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc.

[0266] Figure 12 A block diagram of an example of a computer-readable medium 1300 according to some exemplary embodiments of the present disclosure is shown. The computer-readable medium 1200 has a program 1230 present thereon. Note that although in Figure 12 The computer-readable medium 1200 is depicted in the form of a CD or DVD, but the computer-readable medium 1200 may also be any other form suitable for carrying or storing the program 1230.

[0267] Generally, the various embodiments of this disclosure can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while others may be implemented in firmware or software, which may be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of this disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, as non-limiting examples, the blocks, apparatuses, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0268] This disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions (such as those included in program modules) that are executed in a device on a target real or virtual processor to perform the functions described above. Figure 7 , Figure 8 , Figure 9 or Figure 10 Methods 700, 800, 900, or 1000 are described. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc., that perform specific tasks or implement specific abstract data types. The functionality of a program module can be combined or split among program modules as needed in various embodiments. The machine-executable instructions for a program module can be executed on a local or distributed device. In a distributed device, a program module can reside on both local and remote storage media.

[0269] Program code used to perform the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that, when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0270] In the context of this disclosure, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.

[0271] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof. More specific examples of computer-readable storage media include electrical connections having one or more lines, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. As used herein, the term “non-transient” refers to limitations inherent in the medium itself (i.e., tangible, not signaling), rather than limitations on the persistence of data storage (e.g., RAM and ROM).

[0272] Furthermore, although the operations are described in a specific order, this should not be construed as requiring that these operations must be performed in the specific order or sequence shown, or that all of the operations shown must be performed to achieve the desired result. In some cases, multitasking and parallel processing may be more advantageous. Similarly, although several specific implementation details are included in the foregoing discussion, these implementation details should not be considered as limiting the scope of this disclosure, but rather as a description of features that may be specific to a particular embodiment. Certain features described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0273] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that the disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms of implementing the claims.

Claims

1. A first device, comprising: At least one processor; as well as At least one memory, the at least one memory storing instructions, the instructions, when executed by the at least one processor, cause the first device to at least: Receive a request for encryption credentials from a second device used to perform network functions; Collect information about the network functions; The identifier for the network function is selected based on the collected information; Obtain the cryptographic credentials associated with the selected identifier; as well as Send the encryption credential associated with the selected identifier to the second device.

2. The first device of claim 1, wherein the encryption credential includes a certificate, wherein the request for the encryption credential includes a Certificate Signing Request (CSR), and wherein the first device is further configured to: Send the selected identifier and the CSR to the third device to request the certificate; and Receive the certificate associated with the selected identifier from the third device.

3. The first device of claim 1, wherein the encryption credential includes a certificate, wherein the request for the encryption credential includes a Certificate Signing Request (CSR), and wherein the first device is further configured to: The certificate associated with the selected identifier is obtained from a plurality of certificates received from a third device.

4. The first device of claim 1, wherein the cryptographic credential comprises a token, and wherein the first device is further configured to: The token is generated, and the token includes the identifier and attribute information of the network function.

5. The first device of claim 4, wherein the request for the cryptographic credential includes a public key, and wherein the first device is further configured to generate the token based on the public key.

6. The first device according to any one of claims 1 to 5, wherein the first device is further configured to: Sending a subscription request to a third device to request network function registration, wherein the subscription request includes: The certificate of the node where the first device is deployed.

7. The first device according to any one of claims 1 to 6, wherein the first device is further configured to: Receive a list of identifiers from a third device, wherein the identifiers in the list are associated with a plurality of network functions, and wherein the identifiers for the network functions are selected from the list.

8. The first device of claim 7, wherein the plurality of network functions associated with the identifiers in the list are registered by the fourth device to the third device.

9. The first device according to any one of claims 1 to 8, wherein the first device is configured to collect information about the network function by: Based on the operation of registering the network function, information about the network function is collected from the operating system (OS) or cluster manager, and the operation is performed by a fourth device.

10. The first device according to any one of claims 1 to 9, wherein the information regarding the network function includes at least one of the following: a hash of an image of the network function, a hash of a configuration file of the network function, or a unique identifier of the network function.

11. The first device according to any one of claims 1 to 10, wherein the first device and the second device are both located in a node or a virtual machine.

12. The first device according to any one of claims 1 to 11, wherein the first device sends the encryption credential associated with the selected identifier to the second device by: The cryptographic credentials associated with the selected identifier are sent to the second device along with the certificate chain of the third device.

13. The first device according to any one of claims 1 to 12, wherein at least one of the following: The first device includes an initial trusted IT agent; The third device includes: Certificate Authority (CA) servers, or devices used by NRFs to perform network repository functions; or The fourth device includes: operation, management and maintenance of OAM equipment.

14. A second device for performing network functions, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the second device to at least: Send a request for the encryption credential to the first device; and Receive the encrypted credentials associated with the identifier from the first device. The identifier is selected by the first device based on information about the network functions to be performed by the second device, and the information is collected by the first device.

15. The second device of claim 14, wherein the encryption credential includes a certificate, wherein the request for the encryption credential includes a Certificate Signing Request (CSR), and wherein the certificate associated with the identifier is received by the first device from the third device.

16. The second device of claim 14, wherein the encryption credential includes a certificate, wherein the request for the encryption credential includes a Certificate Signing Request (CSR), and wherein the certificate associated with the selected identifier is obtained from a plurality of certificates received from a third device.

17. The second device of claim 14, wherein the cryptographic credential includes a token, and wherein the token includes the identification and attribute information of the network function.

18. The second device of claim 17, wherein the request for the cryptographic credential includes a public key, and wherein the token is generated by the first device based on the public key.

19. The second device according to any one of claims 14 to 18, wherein the first device and the second device are both located in a node or a virtual machine.

20. The second device according to any one of claims 14 to 19, wherein the information regarding the network function includes at least one of the following: a hash of an image of the network function, a hash of a configuration file of the network function, or a unique identifier of the network function.

21. The second device according to any one of claims 14 to 19, wherein the second device is configured to receive the cryptographic credential associated with the identifier by: The encrypted credentials associated with the identifier are received from the certificate chain of the first device and the third device.

22. The second device according to any one of claims 14 to 21, wherein the second device is further configured to: Based on the determination that a network function configuration file is missing from the network function, a request for the network function configuration file is sent to the fourth device along with the encryption credentials; and The fourth device receives a signed version of the network function profile from the fourth device, wherein the fourth device selects the signed version of the network function profile based on the cryptographic credentials.

23. The second device according to any one of claims 14 to 22, wherein the second device is further configured to: Register the device to perform the Network Repository Function (NRF) by submitting a signed version of the configuration file for the network function and the cryptographic credentials.

24. The second device according to any one of claims 14 to 23, wherein at least one of the following: The first device includes an initial trusted IT agent; The third device includes: Certificate Authority (CA) servers, or devices used by NRFs to perform network repository functions; or The fourth device includes: operation, management and maintenance of OAM equipment.

25. A third device includes: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the third device to at least: Receive configuration information from the fourth device; as well as The fourth device receives registration information about a network function, wherein the registration information includes: the identifier of the network function and the attribute information of the network function.

26. The third device of claim 25, wherein the attribute information includes at least one of the following: a hash of the image of the network function, a hash of the configuration file of the network function, or a unique identifier of the network function.

27. The third device according to claim 25 or 26, wherein the third device is further configured to: Select a first device, which corresponds to an identifier of the node where the network function is deployed, wherein the first device has already subscribed to the third device by sending a subscription request; and A list of identifiers is sent to the selected first device, wherein the identifiers in the list are associated with a plurality of network functions.

28. The third device of claim 27, wherein the network function is deployed by the fourth device via a cluster manager, and wherein the fourth device receives first information about the node and second information about the network function from the cluster manager, and assigns the identifier to the network function.

29. The third device according to claim 28, wherein the first information includes: The network is deployed on the node's identifier, and the second information includes a unique identifier for the network function.

30. The third device according to any one of claims 27 to 29, wherein the first device includes an initial trust IT agent.

31. The third device according to any one of claims 25 to 30, wherein the third device includes a Certificate Authority (CA) server, the CA server being separate from the device used to perform the Network Repository Function (NRF).

32. The third device according to any one of claims 25 to 30, wherein the third device comprises: A CA server implemented by a device used to execute NRF.

33. The third device according to claim 32, wherein the configuration information includes trust domain information.

34. The third device according to any one of claims 25 to 33, wherein at least one of the following: The network function is performed by a second device; and The fourth device includes: Operate, manage, and maintain OAM equipment.

35. A fourth device, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the fourth device to at least: Configure the third device using the configuration information; as well as The network function is registered with the third device by sending registration information about the network function, wherein the registration information includes: the identifier of the network function and the attribute information of the network function.

36. The fourth device according to claim 34, wherein the attribute information includes at least one of the following: a hash of the image of the network function, a hash of the configuration file of the network function, or a unique identifier of the network function.

37. The fourth device according to claim 35 or 36, wherein the fourth device is further configured to: Retrieve the basic image of the network function; An updated image is generated by adding a layer with a configuration file that has the aforementioned network functionality; and The updated image is uploaded to the image repository device.

38. The fourth device according to claim 37, wherein the fourth device is further configured to: The updated signature of the image is uploaded to the image repository device.

39. The fourth device according to claim 37 or 38, wherein the fourth device is further configured to generate the updated image by adding a signed version of the configuration file.

40. The fourth device according to any one of claims 37 to 39, wherein the fourth device is further configured to: The updated image is stored together with the metadata of the network function, wherein the metadata includes at least one of the following: the identifier of the network function, or a sliding identifier.

41. The fourth device according to claim 35 or 36, wherein the fourth device is further configured to: Deploy the network functionality via cluster manager; Receive first information about the node where the network function is deployed, and second information about the network function; and Assign the identifier to the network function.

42. The fourth device according to claim 41, wherein the first information includes: The network is deployed on the node's identifier, and the second information includes a unique identifier for the network function.

43. The fourth device according to any one of claims 35 to 42, wherein the fourth device is further configured to: A request for a network function profile is received from a second device used to perform the network function, along with encrypted credentials from the network function. Select the version of the signature for the network function configuration file based on the encryption credentials; and Send the signed version of the network function configuration file to the second device.

44. The fourth device according to any one of claims 35 to 43, wherein at least one of the following: The third device includes: Certificate Authority (CA) servers, or devices used by NRFs to perform network repository functions; or The fourth device includes: operation, management and maintenance of OAM equipment.

45. A method performed by a first device, comprising: Receive a request for encryption credentials from a second device used to perform network functions; Collect information about the network functions; The identifier for the network function is selected based on the collected information; Obtain the cryptographic credentials associated with the selected identifier; as well as Send the encryption credential associated with the selected identifier to the second device.

46. ​​A method performed by a second device for performing network functions, comprising: Send a request for the encryption credential to the first device; as well as Receive the encrypted credentials associated with the identifier from the first device. The identifier is selected by the first device based on information about the network functions to be performed by the second device, and the information is collected by the first device.

47. A method performed by a third device, comprising: Receive configuration information from the fourth device; as well as The fourth device receives registration information about a network function, wherein the registration information includes: the identifier of the network function and the attribute information of the network function.

48. A method performed by a fourth device, comprising: Configure the third device using the configuration information; as well as The network function is registered with the third device by sending registration information about the network function, wherein the registration information includes: the identifier of the network function and the attribute information of the network function.

49. A computer-readable medium comprising program instructions stored thereon for performing at least the method according to any one of claims 45 to 48.