Certificate Management Microservice

The certificate management microservice addresses security challenges in cloud-native RAN and distributed networks by initializing and managing digital certificates within a secure storage element, enabling secure communication and efficient certificate renewal processes.

JP2025515719AActive Publication Date: 2025-05-20RAKUTEN SYMPHONY INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024566274
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-04
Filing Date
2023-03-08
Publication Date
2025-05-20
Estimated Expiration
2043-03-08

AI Technical Summary

Technical Problem

Cloud-native radio access networks (RAN) and other distributed networking systems face security challenges due to fragmented software and the use of off-the-shelf hardware from multiple vendors, which complicates secure communication among heterogeneous and highly distributed microservices.

Method used

A certificate management microservice is introduced to manage digital certificates in cloud-native networks. This microservice initializes by writing certificates to a secure storage element and provides certificate information to other microservices upon request, enabling secure communication and certificate renewal processes.

Benefits of technology

The certificate management microservice enhances security and efficiency in cloud-native networking by enabling secure communication among microservices, supporting multiple registration protocols, and automating certificate renewal, thus addressing the security vulnerabilities inherent in cloud-native RAN and other distributed networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025515719000001_ABST
    Figure 2025515719000001_ABST
Patent Text Reader

Abstract

A method of operating a cloud-native function (CNF) includes receiving a configuration instruction at a certificate management microservice of the CNF. In response to the configuration instruction, the certificate management microservice is initialized, which includes writing a certificate, including a certificate key, to a secure storage element. The certificate management microservice receives service requests from other microservices of the CNF and, in response to the service requests, transmits certificate information to the other microservices. The certificate information is available for the other microservices to read the certificate key from the secure storage element.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] Priority claim This application claims priority to Indian Provisional Patent Application No. 202241056984, filed on October 4, 2022, which is incorporated herein by reference in its entirety.

[0002] The present disclosure relates to wireless communications, and more specifically, to a certificate management microservice for distributed networking nodes in cloud-native radio access network (RAN) and non-RAN applications. [Background technology]

[0003] In general, cloud-native networks, e.g., RAN and open RAN architectures, provide a large number of services and critical applications. A disaggregated, virtualized, multi-vendor system with many large players is susceptible to security vulnerabilities. Security mechanisms in traditional RAN and other networks are relatively straightforward when all software and hardware in the baseband are dedicated and provided by a single vendor. However, this is not the case in new architectures such as cloud-native RAN. Summary of the Invention

[0004] In cloud-native RAN (virtualized RAN or vRAN) or other networks, the software may be fragmented and often runs on off-the-shelf hardware, whereas in open RAN or other open networks, the software may come from many different vendors. In a cloud-native approach, where the network operation is based on cloud-native network functions (CNFs), the software is containerized with the baseband software split into containerized microservices: PHY, RLC, MAC, transport, and other functions. These microservices are typically coordinated in a Kubernetes cluster and need to communicate securely with each other to function reliably. The communication may be managed by a cloud-native entity called a "service mesh", which includes two parts: (1) a control plane that sets up communication channels between the microservices, and (2) a data plane that manages the transfer of the actual data. The microservices are heterogeneous and highly distributed, and may run on multiple different servers that may be geographically and logically separated and provided by different vendors, each providing different baseband functions. [Means for solving the problem]

[0005] In some embodiments, a method of operating a CNF includes receiving a configuration instruction at a certificate management microservice of the CNF and initializing the certificate management microservice in response to the configuration instruction. Initializing the certificate management microservice includes writing a certificate, including a certificate key, to a secure storage element. The method further includes receiving, at the certificate management microservice, a service request from another microservice of the CNF and sending certificate information to the other microservice in response to the service request. The certificate information is configured to be available for use by the other microservice to read the certificate key from the secure storage element.

[0006] In some embodiments, a method for managing digital certificates in a cloud network includes sending a service request from an active microservice of a CNF of the cloud network to a certificate management microservice of the CNF, sending certificate information from the certificate management microservice to the active microservice in response to receiving the service request, and using the active microservice to read a certificate key from a secure storage element based on the certificate information.

[0007] In some embodiments, a computer-readable medium includes instructions executable by a controller of a network device, e.g., a virtual network function (VNF), that, when executed, cause the controller to perform a predetermined operation. The predetermined operation includes receiving a configuration instruction at a certificate management microservice of the CNF and instantiating the certificate management microservice in response to the configuration instruction. Instantiating the certificate management microservice includes writing a certificate, including a certificate key, to a secure storage element. The predetermined operation further includes receiving, at the certificate management microservice, a service request from another microservice of the CNF and sending certificate information to the other microservice in response to the service request. The certificate information is configured to be available to the other microservice to read the certificate key from the secure storage element.

[0008] Aspects of the present disclosure are best understood from the following detailed description when read in conjunction with the accompanying drawing figures. In accordance with standard industry practice, various features are not drawn to scale. In fact, dimensions of various features have been arbitrarily expanded or reduced for clarity of discussion. [Brief description of the drawings]

[0009] [Figure 1A] FIG. 1 is a diagram of a communication system according to some embodiments. [Figure 1B] FIG. 1 is a diagram of a communication system according to some embodiments.

[0010] [Diagram 2] 1 is a flowchart of a certificate management method according to some embodiments.

[0011] [Diagram 3] 1 is a flowchart of a certificate management method according to some embodiments.

[0012] [Figure 4]1 is a flowchart of a certificate management method according to some embodiments.

[0013] [Diagram 5] FIG. 1 illustrates a method for managing certificates according to some embodiments. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0014] The following disclosure provides many different embodiments or examples for implementing different features of the provided subject matter. To simplify the disclosure, specific examples of components and arrangements are described below. Of course, these are merely examples and are not intended to be limiting. For example, the formation or location of a first feature above or on a second feature (element, part) in the following description includes embodiments in which the first feature and the second feature are formed or arranged in direct contact with each other, and includes embodiments in which an additional feature is formed or arranged between the first feature and the second feature such that the first feature and the second feature are in direct contact with each other. In addition, the present disclosure repeats reference numbers and / or signs in various examples. This repetition is for the purpose of brevity and clarity, and does not in itself dictate a relationship between the various embodiments and / or configurations discussed.

[0015] Additionally, spatially relative terms such as "beneath," "below," "lower," "above," "upper," and the like are used herein for ease of description to describe the relationship of one element or feature to another element(s) or feature(s) as shown in the figures. Spatially relative terms are intended to encompass different orientations of the system or object during use or operation in addition to the orientation shown in the figures. The system may be otherwise oriented (rotated 90 degrees or at other orientations) and the spatially relative descriptors used herein interpreted accordingly.

[0016] In various embodiments, the method and computer readable medium include receiving a configuration instruction at a certificate management microservice of the CNF and initializing the certificate management microservice in response to the configuration instruction. Initializing the certificate management microservice includes writing a certificate, including a certificate key, to a secure storage element. The method and computer readable medium also include receiving a service request at the certificate management microservice from another microservice of the CNF and sending certificate information to the other microservice in response to the service request. The certificate information is configured to be available for use by the other microservice to read the certificate key from the secure storage element. In some embodiments, the method includes one or more of sending an enrolment request from the certificate management microservice to a certification authority (CA), using the certificate management microservice to detect an elapsed time beyond a renewal threshold for the certificate, and sending an enrolment renewal request from the certificate management microservice to the CA in response to detecting the elapsed time beyond the renewal threshold. The enrolment request corresponds to the indicated certificate enrolment protocol. In some embodiments, the method includes sending an initial enrolment renewal request and periodically sending subsequent enrolment renewal requests from the certificate management microservice to the CA.

[0017] By performing some or all of the method operations, a microservice level certificate manager can be easily packaged into RAN CNFs, e.g., CUCP, CUUP, 5G DU, and non-RAN CNFs, e.g., Kafka, EMS, FCAPS services, that require operator certificates, can be easily extended to support any new registration and re-registration protocols, provides gRPC and JSON API based interfaces to communicate with other microservices in the CNF, can communicate with Registration Authorities (RAs) and Certificate Authorities (CAs) for registration and re-registration as controlled for various customer needs, and can support default certificates usable in customer lab trials and proof of concept (POC), e.g., based on the absence of a CA. The certificate management microservice thereby supports multiple registration and re-registration protocols, e.g., selectable algorithms while instantiating the CNF based on customer needs, re-registration of certificates within a configurable window before expiration, notifying applications of changes in device certificates and keys, vendor certificate-based authentication and TLS-SRP equivalent methods for registration, single or multiple certificates for applications, use of a secure vault for storing keys, various certificate profiles corresponding to 3GPP and O-RAN specifications, and operator-specified alarms when registration or re-registration fails. Compared to other approaches, e.g., namespace-level or cluster-level certificate management offered by Kubernetes (K8s), digital certificates can be managed more extensively and more efficiently automatically in cloud-native networking applications, e.g., RAN and Open RAN applications.

[0018] Figure 1A is a diagram of a network system 100 (hereinafter referred to as "system 100") according to some embodiments, and Figure 1B is a diagram of a portion of system 100 according to some embodiments. Figures 1A and 1B are simplified for illustrative purposes.

[0019] System 100 includes multiple interconnected devices 102 configured as part or all of a network 104. In various embodiments, devices 102 correspond to a combination of computing devices, computing systems, servers, server clusters, and / or multiple server clusters, also referred to in some embodiments as a server farm or data center. The combination of interconnected devices 102 includes processing circuitry configured such that it is operable to perform some or all of the various operations described herein.

[0020] In some embodiments, one or more of the devices 102 are virtualized network components, e.g., virtualized network functions (VNFs), such as cloud-native network functions (CNFs), which include software configured to implement one or more network functions by executing on one or more hardware devices. In some embodiments, some or all of the devices 102 are configured as part or all of a network function virtualization infrastructure (NFVI). Other configurations and / or types of devices 102 are within the scope of this disclosure.

[0021] FIG. 1A shows two instances of device 102, namely device 102U and CNF 120, each of which is discussed further below.

[0022] In some embodiments, the network 104 includes one or more Radio Access Networks (RANs) or portions of a RAN. In some embodiments, the RAN is a mobile communication system that implements a Radio Access Technology (RAT) and exists among instances of User Equipment (UE) 112, e.g., mobile phones, computers, etc., and provides connectivity to the devices 102. In some embodiments, the RAN is an Open RAN (O-RAN).

[0023] In some embodiments, one or more of the devices 102 are configured to perform management functions corresponding to the network 104. In various embodiments, one or more of the devices 102 are configured as one or more of an operations support system (OSS), an element management system (EMS), a network management system (NMS), an access and mobility management function (AMF), or other system or function configured to perform one or more activities in support of the operation of the network 104.

[0024] In some embodiments, one or more of the interconnected devices 102 of the network 104 are configured as one or more of a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), an internet area network (IAN), a campus area network (CAN), or a virtual private network (VPN). In some embodiments, one or more of the interconnected devices 102 of the network 104 are configured as part of a backbone or core network (CN), a computer network that interconnects networks and provides a path for exchanging information between different LANs, WANs, etc.

[0025] In some embodiments, some of the interconnected devices 102 of the network 104 are configured as server clusters, for example contained in a data center. In some embodiments, the server clusters are part of a cloud computing environment.

[0026] In some embodiments, the network 104 is some or all of a Global System for Mobile Communications (GSM) RAN, a GSM / EDGE RAN, a Universal Mobile Telecommunications System (UMTS) RAN (UTRAN), an Evolved Universal Terrestrial Radio Access Network (E-UTRAN), an Open RAN (O-RAN), or a Cloud-RAN (C-RAN). In some embodiments, the network 104 resides between the UE 112 and one or more core networks of the system 100.

[0027] In some embodiments, network 104 is part or all of a hierarchical telecommunications network (e.g., system 100) that includes one or more intermediate links, also referred to in some embodiments as a backhaul portion, between the RAN and one or more core networks. Non-limiting examples of mobile backhaul implementations include fiber-based backhaul, wireless point-to-point backhaul, copper-based wireline, satellite communications, and point-to-multipoint wireless technologies. In some embodiments, backhaul refers to the side of the network that communicates with the global Internet.

[0028] 1A, network 104 includes cells 106A and 106B, which include respective base stations 108A and 108B and respective antennas 110A and 110B. In some embodiments, network 104 includes multiple cells, including cells 106A and 106B, collectively referred to as cells 106, or in some embodiments, referred to as coverage area 106, multiple base stations, including base stations 108A and 108B, collectively referred to as base stations 108, and multiple antennas, including antennas 110A and 110B, collectively referred to as antennas 110.

[0029] 1A, a single base station 108 corresponds to a single instance of each of the cell 106 and the antennas 110. In various embodiments, a single base station 108 corresponds to two or more instances of the cell 106 and / or two or more instances of the antennas 110.

[0030] In some embodiments, the base station 108 is a lattice or self-supported tower, a guyed tower, a monopole tower, and a hidden tower (e.g., a tower designed to resemble a tree, a cactus, a water tower, a sign, a lighting standard, and other types of structures). In some embodiments, the base station 108 is a cellular-enabled mobile device site where antennas and electronic communication equipment are typically placed on a radio mast, tower, or other elevated structure to create a cell 106 (or adjacent cells) in the network. The elevated structure typically supports the antenna(s) 110 and one or more sets of transmitters / receivers, transceivers, digital signal processors, control electronics, remote radio heads (RRHs), primary and backup power sources, and shelters. The base station 108 is known by other names such as a base transceiver station, a cellular phone mast, or a cell tower. In some embodiments, the base station 108 is an edge device configured to wirelessly communicate with the UEs 112. Edge devices provide an entry point into a service provider core network, and examples include routers, routing switches, integrated access devices (IADs), multiplexers, and various MAN and WAN access devices.

[0031] In at least one embodiment, an example of antenna 110 is a sector antenna, e.g., a directional microwave antenna having a sector-shaped radiation pattern, or a multiple sector antenna configured to have, e.g., a full-circle coverage area 106. In some embodiments, an instance of antenna 110 is a circular antenna. In some embodiments, an instance of antenna 110 operates at one or more microwave or ultra-high frequency (UHF) frequencies, e.g., in the range of 300 megahertz (MHz) to 7.2 gigahertz (GHz). In some embodiments, an instance of antenna 110 operates at one or more frequencies in the range of 24.2 GHz to 71.0 GHz.

[0032] In various embodiments, the cell 106 is a three-dimensional space having a shape and size based on the configuration, e.g., power levels, and antennas 110, e.g., several sectors, of the corresponding base station 108. In various embodiments, the cell 106 has a substantially spherical, hemispherical, conical, cylindrical, circular or elliptical disk, or other shape corresponding to the base station and antenna configuration. In various embodiments, one or both of the shape or size of the cell 106 changes over time, e.g., based on variable base station power levels and / or variable numbers of activated antennas and / or antenna sectors. In some embodiments, the cell 106 is referred to as a macro cell, a micro cell, a pico cell, a femto-cell, or a small cell. In some embodiments, the cell 106 is referred to as an indoor small cell (IDSC).

[0033] In some embodiments, an instance of UE 112 is a computer or computing system. In some embodiments, an instance of UE 112 has a graphical user interface that provides a liquid crystal display (LCD), light emitting diode (LED), or organic light emitting diode (OLED) screen interface, e.g., a touch screen interface with digital buttons and a keyboard, or physical buttons with a physical keyboard. In some embodiments, an instance of UE 112 connects to the Internet and interconnects with other devices. In some embodiments, an instance of UE 112 incorporates a built-in camera, voice and video phone call capabilities, video games, and global positioning system (GPS) capabilities. In some embodiments, an instance of UE 112 functions as a virtual machine or runs third party apps as a container. In some embodiments, an instance of a UE 112 is a computer (such as a tablet computer, a netbook, a digital media player, a digital assistant, a graphing calculator, a handheld game console, a handheld personal computer (PC), a laptop, a mobile internet device (MID), a personal digital assistant (PDA), a pocket calculator, a portable media player, or an ultra-mobile PC), a mobile phone (such as a camera phone, a feature phone, a smartphone, or a phablet), a digital camera (such as a digital camcorder, or a digital still camera (DSC), a digital video camera (DVC), or a front-facing camera), a pager, a personal navigation device (PND), a wearable computer (such as a calculator watch, a smart watch, a head mounted display, an earpiece, or a biometric device), or a smart card.

[0034] The UE 112 is configured to communicate with the base station 108 via signals transmitted to and from the antenna 110 .

[0035] The network 104 includes multiple network nodes, referred to in some embodiments as nodes or RAN nodes. In some embodiments, a node corresponds to one or more devices 102, a combination of one or more devices 102 and one or more base stations 108, or one or more base stations 108. In some embodiments, a node corresponds to a base station 108 that is an instance of a device 102.

[0036] In some embodiments, the nodes correspond to a device 102 configured as a centralized unit (CU) and one or more base stations 108 configured as distributed units (DUs). In some embodiments, the nodes are next generation RAN (NG-RAN) nodes, such as gNBs and NG-eNBs according to the 3GPP TS 38.300 specification.

[0037] The nodes are interconnected to each other and to a network management entity, e.g., an EMS or AMF, via various interfaces. In some embodiments, the interfaces between the nodes and the core network elements are referred to as NG interfaces. In some embodiments, the interfaces between various nodes, e.g., between NG-RAN nodes, are referred to as Xn interfaces.

[0038] 1A, device 102U is a device configured to deploy one or more applications to network 104. Device 102U includes a storage device 114U configured to store microservice generator 116U and configuration parameters 118U. In the embodiment shown in FIG. 1A, device 102U is a single instance of device 102. In some embodiments, device 102U includes multiple instances of device 102.

[0039] A storage device, e.g., storage device 114U, is one or more computer-readable non-volatile storage media including one or more of dynamic memory (e.g., RAM, magnetic disk, writable optical disk, etc.) and static memory (e.g., ROM, CD-ROM, etc.) configured to store executable instructions that, when executed, perform operations described herein to facilitate automated certificate management. In some embodiments, storage device 114U is also configured to store data associated with or generated by the execution of operations, e.g., configuration parameters 118U.

[0040] 1A, storage device 114U is located on device 102U. In some embodiments, storage device 114U is located partially or wholly outside device 102U, for example, on one or more servers corresponding to device 102U.

[0041] Microservice generator 116U is a set of one or more instructions configured to execute on device 102U to deploy and / or manage CNF 120 on network 104. Configuration parameters 118U is a set of data records configured to be usable by CNF 120, as described below with respect to method 200.

[0042] CNF 120 is an application configured to perform one or more networking functions or applications for network 104. In some embodiments, CNF 120 comprises a CU CNF or a DU CNF of a RAN or O-RAN. In some embodiments, CNF 120 comprises one of CNFs 120A-120C discussed below with respect to FIG. 1B. In some embodiments, CNF 120 is an application of a network other than a RAN or O-RAN.

[0043] CNF 120 includes a certificate management microservice 122 and additional microservices 124. Each of certificate management microservice 122 and additional microservices 124, as components, e.g., pods, of CNF 120, includes a set of instructions configured to perform one or more networking functions. In operation, certificate management microservice 122 and additional microservices 124 are configured to communicate with each other via one or more application programming interfaces (APIs), e.g., gRPC / JSON APIs.

[0044] The CNF 120 and the certificate management microservice 122 are configured to perform some or all of the operations of the method 200 discussed below with respect to Figures 2-5.

[0045] 1B, system 100 includes a network 104 configured as a RAN or O-RAN that includes three instances of CNF 120, CNFs 120A-120C, and an instance of device 102, CA server 102CA. CNF 120A is configured as a gNB-CU-CP (control plane) CNF, CNF 120B is configured as a gNB-CU-UP (user plane) CNF, and CNF 120C is configured as a gNB-DU CNF.

[0046] CA server 102 CA includes one or more servers configured as a certification authority (CA) and an entity configured to store, sign, and issue digital certificates according to one or more enrollment procedures based on one or more certificate enrolment protocols.

[0047] Each of CNFs 120A-120C includes an instance of a certificate management microservice 122, CertMgr, and an instance of additional microservice 124, uS-2 through uS-N, corresponding to a total of N microservices. During operation, microservices CertMgr and uS-2 through uS-N are configured to communicate via gRPC messages, e.g., to send and receive service messages.

[0048] Each instance of CertMgr is configured to read and write digital certificate information, e.g., a digital certificate including a public key, to a corresponding instance of the secure vault SecVault, and each instance of microservices uS-2 through uS-N is configured to read digital information from a corresponding instance of the secure vault SecVault.

[0049] 1B, each instance of CertMgr is configured as a first microservice of a corresponding CNF 120A-120C. In some embodiments, one or more instances of CertMgr are configured as different microservices of the corresponding CNF 120A-120C, such that the first microservice uS-1 is included in additional microservice 124.

[0050] CNFs 120A-120C, including instances of CertMgr, are configured to perform some or all of the operations of method 200 discussed below with respect to FIGS.

[0051] Thus, system 100, including one or more instances of CNF 120 as discussed above to perform some or all of method 200, is configured to obtain the advantages discussed below with respect to method 200.

[0052] 2 is a flowchart of a certificate management method 200 according to some embodiments. The certificate management method 200, also referred to in some embodiments as method 200, or a method of operating a CNF, is operable on a network system, such as the system 100 discussed above with respect to FIGS. 1A and 1B.

[0053] Additional operations may be performed before, during, and / or after the method 200 shown in Figure 2, and some other operations may only be briefly described herein. In some embodiments, other orders of the operations of method 200 are within the scope of this disclosure. In some embodiments, one or more operations of method 200 are not performed.

[0054] In some embodiments, some or all of the operations of method 200 are included in another method, e.g., a method of operating a networking system. In some embodiments, some or all of the operations of method 200 discussed below are repeated, e.g., as part of the operation of a network system.

[0055] In some embodiments, some or all of the operations of method 200 discussed below may be performed automatically by CNF 120, including, for example, certificate management microservice 122, discussed above with respect to Figures 1A and 1B, respectively.

[0056] The operation of the method 200 is discussed below with reference to various features of the system 100 discussed above with respect to FIGS. 1A and 1B.

[0057] 3-5 show non-limiting examples illustrating the performance of some or all of the operations of method 200 using an embodiment of system 100, as discussed below.

[0058] At operation 210, in some embodiments, a configuration instruction is received at a certificate management microservice of a CNF. In some embodiments, receiving the configuration instruction includes receiving a set of day 0 parameters, e.g., the example day 0 parameters presented in Table 1 below. In some embodiments, receiving the configuration instruction at the certificate management microservice of the CNF includes receiving configuration parameters 118U at a certificate management microservice 122 of a CNF 120, e.g., at a CertMgr of one of CNFs 120A-120C.

[0059] In some embodiments, receiving the configuration instructions at the certificate management microservice of the CNF includes deploying, e.g., using microservice generator 116U, one or more of the certificate management microservice, the CNF, or an application that includes the certificate management microservice and the CNF. In various embodiments, deploying one or more of the certificate management microservice, the CNF, or the application includes starting a new instance of the certificate management microservice, the CNF, or the application, or performing updates to an existing certificate management microservice, the CNF, or the application.

[0060] In some embodiments, deploying one or more of the certificate management microservices, CNFs, or applications includes entering an operational mode in which the one or more of the certificate management microservices, CNFs, or applications are configured to wait to receive instructions.

[0061] In some embodiments, receiving the configuration instruction at the certificate management microservice includes receiving a push from a network device, such as device 102U. In some embodiments, receiving a push from a network device includes receiving a push from a network operator.

[0062] In operation 220, in some embodiments, a certificate management microservice is initialized. In some embodiments, initializing the certificate management microservice includes initializing the certificate management microservice 122 of a CNF 120, e.g., CertMgr of one of CNFs 120A-120C.

[0063] In some embodiments, initializing the certificate management microservice corresponds to performing day 0 operations. In some embodiments, initializing the certificate management microservice corresponds to instantiating one or more application pods.

[0064] In some embodiments, initializing the certificate management microservice is based on the received configuration instructions, such as configuration parameters 118U. In some embodiments, initializing the certificate management microservice is based on the day 0 parameters in Table 1 below. [Table 1]

[0065] A non-limiting example of the set of day 0 parameters presented in Table 1 includes, for each day 0 parameter listed in the first column, a description in the second column and an indication in each subsequent column as to whether the day 0 parameter needs to be defined for a corresponding one of the four defined certificate enrollment protocols, namely, VNF Certificate Management Protocol version 2 (CMPv2), VNF Enrollment over Secure Transport (EST), Physical Network Function (PNF) (CMPv2) and PNF(EST). The parameters CA FQDN / IP, CA port, CA subject name, CA PATH, shared secret, reference number, and Root CA including issuing CA are identifiers configured to enable communication with a certificate authority, such as CA server 102 CA. The protocol indication is configured to identify the certificate enrollment protocol, such as EST, CMP, CMPv2, or Simple Certificate Enrollment Protocol (SCEP). The parameters TLS username and TLS password are authentication parameters set according to a Transport Layer Security (TLS) Secure Remote Password (SRP) operation with the VNF EST. The parameter host name is an identifier corresponding to a host NF, for example, the CNF 120 .

[0066] In some embodiments, initializing the certificate management microservice includes configuring a certificate enrollment protocol, e.g., in response to the received set of parameters, In some embodiments, configuring the certificate enrollment protocol includes configuring a certificate enrollment protocol corresponding to one of EST, CMP, CMPv2, or SCEP.

[0067] In some embodiments, initializing the certificate management microservice includes determining whether to perform a certificate enrollment procedure, e.g., based on the received configuration instructions. In some embodiments, determining whether to perform a certificate enrollment procedure includes determining that a CA or RA is unavailable, e.g., based on one or more received parameters.

[0068] In some embodiments, initializing the certificate management microservice includes authenticating the certificate management microservice to a secure storage element, e.g., a persistent volume such as a secure vault or non-volatile memory. In some embodiments, authenticating the certificate management microservice to the secure storage element is based on one or more received parameters. In some embodiments, authenticating the certificate management microservice to the secure storage element includes authenticating the certificate management microservice to a secure vault SecVault of one of CNFs 120A-120C.

[0069] In some embodiments, authenticating the certificate management microservice to the secure storage element includes integrating the certificate management microservice with an external secure vault, such as a secure vault requested by an end user of the CNF.

[0070] In some embodiments, authenticating the certificate management microservice to the secure storage element includes deploying the secure storage element, hi some embodiments, deploying the secure storage element includes setting up a secure vault, for example, by using Hashicorp software.

[0071] In some embodiments, initializing the certificate management microservice includes writing one or more certificates to a secure storage element, for example, by performing some or all of operation 230 discussed below.

[0072] A certificate as contemplated herein is a digital certificate configured according to one or more standards such that it can be used by an external entity to attest that the named subject of the certificate has ownership of the public key contained in the certificate. In some embodiments, the certificate has a certificate profile based on 3GPP or O-RAN specifications.

[0073] In some embodiments, initializing the certificate management microservice includes performing a certificate enrollment procedure, which includes performing one of an initial enrolment procedure or a re-enrollment procedure for the given certificate.

[0074] Performing the certificate enrollment procedure includes the certificate management microservice communicating with the CA using a certificate enrollment protocol, e.g., based on one or more CA identifier parameters included in configuration parameters 118U, e.g., based on one or more parameters included in configuration parameters 118U.

[0075] In some embodiments, performing the registration procedure includes performing a procedure corresponding to one of EST, CMP, CMPv2, or SCEP. In some embodiments, performing the registration procedure includes using one or both of libopenssl or libest software.

[0076] In some embodiments, performing the enrollment procedure includes starting a renewal timer that corresponds to performing the enrollment procedure for the given certificate.

[0077] In some embodiments, performing the registration procedure includes one or both of sending a registration renewal request to a certificate authority or sending a renewal notice to a user of the CNF.

[0078] In some embodiments, performing the registration procedure includes iteratively performing the registration procedure for multiple microservices of the CNF.

[0079] At operation 230, in some embodiments, the certificate is written to a secure storage element.

[0080] In some embodiments, writing the certificate to the secure storage element includes writing a certificate that was registered by performing some or all of operation 220 discussed above. In some embodiments, writing the certificate to the secure storage element includes writing a default certificate included in the CNF or linked to the CNF. In some embodiments, writing the certificate to the secure storage element includes writing an operator-signed certificate to the secure storage element.

[0081] In some embodiments, a service request is received at a certificate management microservice at operation 240. Receiving the service request includes receiving a service request that corresponds to a key for a certificate associated with the CNF and stored in a secure storage element.

[0082] Receiving a service request includes receiving a service request from a microservice of the CNF other than the certificate management microservice, or from a management system of the network in which the CNF is deployed, such as a configuration management system (ConfD), a performance management system (PerfMgr), or an IP security management system (IpsecMgr).

[0083] In some embodiments, receiving the service request at the certificate management microservice includes receiving the service request from uS-2 at the certificate management microservice 122 or CertMgr at the additional microservice 124 or from uS-2.

[0084] In some embodiments, receiving the service request at the certificate management microservice includes receiving the service request via an API, for example using a gRPC message.

[0085] In some embodiments, certificate information is sent from the certificate management microservice to a service requesting entity (service requester, service requesting device) at operation 250. Sending the certificate information from the certificate management microservice to the service requesting device includes sending certificate information configured to be usable by the service requesting device to read the certificate and / or certificate key from the secure storage element.

[0086] In some embodiments, sending the certificate information from the certificate management microservice includes sending the certificate information from the certificate management microservice 122 or CertMgr to the additional microservice 124 or from uS-N to uS-2.

[0087] In operation 260, in some embodiments, the service request device is used to read the certificate key of the certificate from the secure storage element. In some embodiments, using the service request device includes, for example, using additional microservices 124 or uS-2 through uS-N to read the certificate key from the SecVault.

[0088] In act 270, in some embodiments, an elapsed time exceeding a certificate renewal threshold is detected. Detecting the elapsed time exceeding the certificate renewal threshold includes the certificate management microservice detecting the elapsed time exceeding the certificate renewal threshold based on starting the renewal timer in act 230.

[0089] In some embodiments, detecting an elapsed time exceeding a certificate renewal threshold includes the certificate renewal threshold being based on a percentage of the validity period of the certificate.

[0090] In some embodiments, a certificate renewal process is initiated at operation 280. In some embodiments, initiating the certificate renewal process includes performing some or all of operation 230 discussed above.

[0091] In some embodiments, sending a registration renewal request from the certificate management microservice to the CA includes sending an initial registration renewal request and periodically sending subsequent registration renewal requests from the certificate management microservice to the CA.

[0092] In some embodiments, initiating the certificate renewal process includes sending a renewal notification to a user of the CNF. In some embodiments, initiating the certificate renewal process includes determining a failure of the renewal process, sending a second enrollment renewal request to the CA based on determining the failure, and sending a failure notification, e.g., an alarm, to the user of the CNF.

[0093] In some embodiments, performing operations 270 and 280 includes performing some or all of the following operations: When the current system date and time exceeds "Certificate Issue Date" + ("Renewal Threshold" * "Certificate Validity Period"), the certificate renewal process is triggered. At the same time, the device generates an alarm "Operator Device Certificate will expire in "n" days". The alarm is cleared after the certificate renewal is successful. For example, if the "certificate validity period" = 100 days and the "renewal threshold" = 60%, certificate renewal is triggered when the current system date exceeds the "certificate issue date" + 60 days. Certificate renewal can be triggered either immediately when the above conditions are met, or a predefined time after the above conditions are met (e.g., one hour after the conditions are met). Since the validity period of a certificate can be several hours, it is useful to ensure that certificate renewal is triggered based on one of the above logics. Upon power-on, if the device finds that the current system date and time is already past the "Certificate Issue Date" + ("Renewal Threshold" * "Certificate Validity Period"), then the device will initiate the certificate renewal process as discussed above. At the same time, the device will generate an alarm that says "Operator Device Certificate will expire in "n" days (n days from now)". This alarm will be cleared after the certificate renewal is successful. Upon power-on, if the device determines that the certificate has already expired, then the device will initiate the certificate enrollment process using other credentials. At the same time, the device will generate an "operator device certificate has expired" alarm. This alarm will be cleared after the certificate enrollment is successful. Virtual machines (VMs) use TLS-SRP credentials provided as part of the day 0 configuration. RU / gNB-DU uses vendor / factory provisioned certificates. If the renewal procedure fails, then the device will periodically retry the certificate renewal at least 10 times during the remaining period (while the certificate is valid). For example, if there are 40 days remaining, then the device will attempt to renew the certificate at least 10 times during this period (until successful), and similarly if there are 4 days remaining.

[0094] By performing some or all of the operations of method 200, a system, such as system 100, performs some or all of the following: receiving a configuration instruction at a certificate management microservice of the CNF; initializing the certificate management microservice in response to the configuration instruction (initializing the certificate management microservice includes writing a certificate, including a certificate key, to a secure storage element); receiving a service request at the certificate management microservice from another microservice of the CNF; and sending certificate information to the other microservice in response to the service request. The certificate information is configured to be usable by the other microservice to read the certificate key from the secure storage element. In some embodiments, the method includes one or more of sending a registration request from the certificate management microservice to the CA (the registration request corresponds to the indicated certificate registration protocol); using the certificate management microservice to detect an elapsed time beyond a renewal threshold of the certificate; and in response to detecting the elapsed time beyond the renewal threshold, sending a registration renewal request from the certificate management microservice to the CA, and in some embodiments, sending an initial (first) registration renewal request and periodically sending subsequent registration renewal requests from the certificate management microservice to the CA.

[0095] By performing some or all of the method operations, the microservices-level certificate manager can be easily packaged into RAN CNFs, e.g., CUCP, CUUP, 5G DU, and non-RAN CNFs, e.g., Kafka, EMS, FCAPS services, that require operator certificates, can be easily extended to support any new registration and re-registration protocols, provides gRPC and JSON API based interfaces to communicate with other microservices in the CNF, can communicate with RAs and CAs for registration and re-registration as controlled for various customer needs, can support default certificates available in customer lab trials and POCs, e.g., based on absence of CA. The certificate management microservice thereby supports multiple registration and re-registration protocols, e.g., selectable algorithms while instantiating the CNF based on customer needs, re-registration of certificates within a configurable window before expiration, notifying applications of device certificate and key changes, vendor certificate based authentication and TLS-SRP equivalent methods for registration, single or multiple certificates for applications, use of secure vaults to store keys, various certificate profiles corresponding to 3GPP and O-RAN specifications, and operator specified alarms when registration or re-registration fails. Compared to other approaches, such as namespace-level or cluster-level certificate management offered by Kubernetes (K8s), digital certificates can be managed automatically more extensively and more efficiently in cloud-native networking applications, such as RAN and Open RAN applications.

[0096] 3 is a flowchart of a certificate management method 300, according to some embodiments. Certificate management method 300, also referred to in some embodiments as method 300 or method of operating CNF 300, is a non-limiting example of some or all of method 200 discussed above.

[0097] Method 300 corresponds to operations 210-250 shown in Figure 3. In the embodiment shown in Figure 3, operation 230 of method 200 corresponds to separate operations 230A and 230B of method 300 based on whether registration is required. If registration is not required, in operation 230A writing a certificate to the secure storage element includes writing one or more default certificates to the secure storage element. If registration is required, in operation 230B writing a certificate to the secure storage element includes writing one or more registered certificates to the secure storage element after performing a registration and / or re-registration process.

[0098] By performing some or all of the operations of method 200 in accordance with the non-limiting example of method 300, the advantages discussed above with respect to FIGS. 1A-2 may be realized.

[0099] 4 is a flowchart of a certificate management method 400, according to some embodiments. Certificate management method 400, also referred to in some embodiments as method 400 or method of operating CNF 400, is a non-limiting example of some or all of method 200 discussed above.

[0100] The method 400 corresponds to acts 220-250 shown in FIG.

[0101] By performing some or all of the operations of method 200 in accordance with the non-limiting example of method 400, the advantages discussed above with respect to FIGS. 1A-2 may be realized.

[0102] 5 is a flowchart of a certificate management method 500, according to some embodiments. Certificate management method 500, also referred to in some embodiments as method 500 or method of operating CNF 500, is a non-limiting example of some or all of method 200 discussed above.

[0103] The method 500 corresponds to acts 240-280 shown in FIG.

[0104] By performing some or all of the operations of method 200 in accordance with the non-limiting example of method 500, the advantages discussed above with respect to FIGS. 1A-2 may be realized.

[0105] In some embodiments, a method of operating a CNF includes receiving a configuration instruction at a certificate management microservice of the CNF, initializing the certificate management microservice in response to the configuration instruction (initializing the certificate management microservice includes writing a certificate including a certificate key to a secure storage element), receiving a service request at the certificate management microservice from another microservice of the CNF, and sending certificate information to the other microservice in response to the service request. The certificate information is configured to be usable by the other microservice to read the certificate key from the secure storage element. In some embodiments, initializing the certificate management microservice includes integrating the certificate management microservice with a secure storage element comprising a secure vault or a persistent volume. In some embodiments, initializing the certificate management microservice further includes setting a certificate enrollment protocol. In some embodiments, initializing the certificate management microservice includes instantiating a certificate manager based on a set of parameters including authentication parameters. In some embodiments, initializing the certificate management microservice includes performing an enrollment procedure for the certificate with a certificate authority based on the set of parameters, and starting a renewal timer corresponding to performing the enrollment procedure for the certificate. In some embodiments, the method includes detecting that an elapsed time of the update timer has exceeded an update threshold, and in response to detecting that the elapsed time has exceeded the update threshold, sending a registration update request to the certificate authority and sending an update notification to a user of the CNF. In some embodiments, the method includes sending a second registration update request to the certificate authority and sending a failure notification to the user of the CNF based on a failure of the registration update request. In some embodiments, writing the certificate including the certificate key to the secure storage element includes writing an operator signed certificate to the secure storage element. In some embodiments, writing the certificate including the certificate key to the secure storage element includes writing a default certificate to the secure storage element.In some embodiments, the CNF includes one of a CU CNF or a DU CNF of a radio access network RAN.

[0106] In some embodiments, a method for managing digital certificates in a cloud network includes sending a service request from an active microservice of a CNF of the cloud network to a certificate management microservice of the CNF, in response to receiving the service request, sending certificate information from the certificate management microservice to the active microservice, and using the active microservice to read a certificate key from a secure storage element based on the certificate information. In some embodiments, the method includes pushing a configuration message to the certificate management microservice, and in response to receiving the configuration message, instantiating the certificate management microservice. Instantiating the certificate management microservice includes writing a certificate, including the certificate key, to the secure storage element. In some embodiments, pushing the configuration message to the certificate management microservice includes pushing a configuration message including a set of configuration parameters including one or more identifiers corresponding to a certificate authority CA and a certificate enrollment protocol. In some embodiments, the method includes sending an enrollment request from the certificate management microservice to the CA based on the one or more identifiers, the enrollment request corresponding to the certificate enrollment protocol. In some embodiments, the method includes using a certificate management microservice to detect an elapsed time beyond a certificate renewal threshold, and in response to detecting the elapsed time beyond the renewal threshold, sending a registration renewal request from the certificate management microservice to a CA. In some embodiments, sending the registration renewal request from the certificate management microservice to the CA includes sending an initial registration renewal request, and the method includes periodically sending subsequent registration renewal requests from the certificate management microservice to the CA. In some embodiments, using the active microservice to read the certificate key includes reading a certificate key corresponding to a certificate profile based on a 3GPP or O-RAN specification.In some embodiments, the active microservice is a first active microservice of a plurality of active microservices of the CNF, and the method includes sending the additional certificate information from the certificate management microservice to a second active microservice of the plurality of active microservices, and using the second active microservice to read another certificate key from the secure storage element based on the additional certificate information. In some embodiments, the cloud network includes an O-RAN.

[0107] In some embodiments, the computer-readable medium includes instructions executable by a network device, such as a controller of a VNF. The instructions cause the controller to perform predetermined operations. The predetermined operations include receiving configuration instructions at a certificate management microservice of the CNF, and in response to the configuration instructions, instantiating the certificate management microservice (instantiation of the certificate management microservice includes writing a certificate, including a certificate key, to a secure storage element), receiving service requests from other microservices of the CNF at the certificate management microservice, and in response to the service requests, sending certificate information to the other microservices. The certificate information is configured to be usable by the other microservices to read the certificate key from the secure storage element.

[0108] The above outlines the features of some embodiments so that those skilled in the art may better understand the aspects of the present disclosure. Those skilled in the art will appreciate that they may easily use this disclosure as a basis for designing or modifying other processes and structures to carry out the same purpose and / or achieve the same advantages of the embodiments introduced herein. Those skilled in the art will also appreciate that such equivalent constructions do not depart from the spirit and scope of the present disclosure, and that those skilled in the art will make various changes, substitutions, and alterations herein without departing from the spirit and scope of the present disclosure.

Claims

1. 1. A method of operating a cloud native network function (CNF), the method comprising: receiving a configuration command at a certificate management microservice of the CNF; and initializing the certificate management microservice in response to the configuration instructions, where initializing the certificate management microservice includes writing a certificate with a certificate key to a secure storage element; The method further comprises: receiving, at the certificate management microservice, a service request from another microservice of the CNF; and in response to the service request, sending certificate information to the other microservice, wherein the certificate information is configured to be usable by the other microservice to read the certificate key from the secure storage element.

2. 2. The method of claim 1, wherein initializing the certificate management microservice further comprises integrating the certificate management microservice with a secure storage element comprising a secure vault or a persistent volume.

3. The method of claim 1 , wherein initializing the certificate management microservice further comprises configuring a certificate enrollment protocol.

4. 2. The method of claim 1, wherein initializing the certificate management microservice further comprises instantiating the certificate manager based on a set of parameters comprising authentication parameters.

5. Initializing the certificate management microservice includes: performing an enrollment procedure for said certificate with a certificate authority based on said set of parameters; starting an update timer corresponding to said performing of said enrollment procedure for said certificate; The method of claim 4 further comprising:

6. detecting when an elapsed time of the update timer exceeds an update threshold; in response to detecting that the elapsed time has exceeded the renewal threshold, sending a registration renewal request to the certificate authority and sending a renewal notification to a user of the CNF; The method of claim 5 further comprising:

7. Upon failure of said registration renewal request, sending a second registration renewal request to the certificate authority; sending a failure notification to the user of the CNF; The method of claim 6 further comprising:

8. The method of claim 1 , wherein writing the certificate with the certificate key to the secure storage element comprises writing an operator signed certificate to the secure storage element.

9. The method of claim 1 , wherein writing the certificate with the certificate key to the secure storage element comprises writing a default certificate to the secure storage element.

10. The method of claim 1 , wherein the CNF comprises one of a centralized unit (CU) CNF or a distributed unit (DU) CNF of a radio access network (RAN).

11. 1. A method for managing digital certificates in a cloud network, the method comprising: Sending a service request from an active microservice of a cloud native network function (CNF) of the cloud network to a certificate management microservice of the CNF; In response to receiving the service request, sending certificate information from the certificate management microservice to the active microservice; using the active microservice to read a certificate key from a secure storage element based on the certificate information; The method includes:

12. The method comprises: Pushing a configuration message to the certificate management microservice; 12. The method of claim 11, further comprising: in response to receiving the configuration message, instantiating the certificate management microservice, wherein instantiating the certificate management microservice comprises writing a certificate with the certificate key to the secure storage element.

13. Pushing the configuration message to the certificate management microservice includes pushing the configuration message comprising a set of configuration parameters, the set of configuration parameters comprising: One or more identifiers corresponding to a certification authority (CA); A certificate enrollment protocol; 13. The method of claim 12, comprising:

14. The method further includes sending an enrollment request from the certificate management microservice to the CA based on the one or more identifiers; The method of claim 13 , wherein the enrollment request corresponds to the certificate enrollment protocol.

15. using the certificate management microservice to detect an elapsed time beyond a renewal threshold for the certificate; In response to detecting an elapsed time exceeding the renewal threshold, sending a registration renewal request from the certificate management microservice to the CA; The method of claim 14 further comprising:

16. Sending the registration renewal request from the certificate management microservice to the CA includes sending an initial registration renewal request; 16. The method of claim 15, further comprising periodically sending subsequent registration renewal requests from the certificate management microservice to the CA.

17. 12. The method of claim 11, wherein using the active microservice to read the certificate key includes reading the certificate key corresponding to a certificate profile based on a 3GPP or an Open Radio Access Network (O-RAN) specification.

18. the active microservice is a first active microservice of a plurality of active microservices of the CNF; The method comprises: Sending additional certificate information from the certificate management microservice to a second active microservice of the plurality of active microservices; and using the second active microservice to read another certificate key from the secure storage element based on the additional certificate information; The method of claim 11 further comprising:

19. The method of claim 11 , wherein the cloud network comprises an open radio access network (O-RAN).

20. 11. A computer-readable medium comprising instructions executable by a controller of a network device, the instructions, when executed, causing the controller to perform an operation, the operation comprising: Receiving a configuration instruction at a cloud native network function (CNF) certificate management microservice; instantiating the certificate management microservice in response to the configuration instructions, where instantiating the certificate management microservice includes writing a certificate with a certificate key to a secure storage element; The operation further comprises: receiving, at the certificate management microservice, a service request from another microservice of the CNF; and in response to the service request, sending certificate information to the other microservice, wherein the certificate information is configured to be usable by the other microservice to read the certificate key from the secure storage element.

Citation Information

Patent Citations

  • Service certificate management method, terminal, and server

    CN111066284A

  • Certificate Renewal and Deployment

    JP2019503115A

  • Secure access to application instances in a multi-user, multi-tenant computing environment

    US20200028848A1

  • Systems and methods for managing public key infrastructure certificates for components of a network

    US20210377054A1

  • Method and system for certificate management

    US20220239503A1