Certificate Enrollment for Shared Network Elements
The O-RAN PKI service provider addresses the lack of secure connections and certificate management in O-RAN systems by issuing certificates to shared O-RUs, enhancing trust and enabling cost-effective network expansion and scalability.
Patent Information
- Application Number
- JP2024537923
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-06-10
- Filing Date
- 2022-10-27
- Publication Date
- 2025-11-10
- Estimated Expiration
- 2042-10-27
AI Technical Summary
Current O-RAN systems lack a clear mechanism for establishing secure connections and certificate management between a common O-RU and multiple O-DUs, particularly in multi-operator deployments, hindering trust exchange and network scalability.
Implementing an O-RAN public key infrastructure (PKI) service provider to issue certificates to shared O-RUs, enabling multiple operators to establish trust relationships and manage certificates, thereby facilitating secure connections and network coverage expansion.
Enables secure communications and expanded network coverage at lower costs by authenticating shared O-RUs using certificates issued by the O-RAN PKI service provider, supporting enhanced functionalities like MORAN and rural coverage.
Smart Images

Figure 0007766808000001 
Figure 0007766808000002 
Figure 0007766808000003
Abstract
Description
[Technical Field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application is based on and claims priority to U.S. Provisional Patent Application No. 63 / 351,142, filed June 10, 2022, the disclosure of which is incorporated herein by reference in its entirety.
[0002] Apparatus and methods consistent with example embodiments of the present disclosure relate to a system for establishing a trust exchange between multiple mobile network operators and providing certificate management for shared Open Radio Access Network (O-RAN) Radio Units (O-RUs). [Background technology]
[0003] The radio access network (RAN) is a critical component in telecommunications systems because it connects end-user devices (or user equipment) to the rest of the network. The RAN includes a combination of various network elements (NEs) that connect end-user devices to the core network. Traditionally, the hardware and / or software of a particular RAN is vendor-specific.
[0004] Open RAN (O-RAN) technology has emerged to enable multiple vendors to provide hardware and / or software for telecommunication systems. To this end, O-RAN divides RAN functions into a centralized unit (CU), a distributed unit (DU), and a radio unit (RU). The CU is a logical node for hosting the Radio Resource Control (RRC), Service Data Adaptation Protocol (SDAP), and / or Packet Data Convergence Protocol (PDCP) sublayers of the RAN. The DU is a logical node for hosting the Radio Link Control (RLC), Media Access Control (MAC), and Physical (PHY) sublayers of the RAN. The RU is a physical node that converts radio signals from the antenna into digital signals that can be transmitted to the DU via the fronthaul. These entities have open protocols and interfaces between them, allowing different vendors to provide nodes (or network elements) within one RAN.
[0005] The current lower layer split architecture in O-RAN (i.e., split between O-RAN RU (O-RU) and O-RAN DU (O-DU)) is constrained by forcing an O-RU node to operate with a single O-DU node, which limits the ability of the fronthaul system to be used to deliver extended use cases where multiple O-DU nodes can be used to extend the functionality delivered using O-RAN open fronthaul specifications.
[0006] A common O-RU (or shared O-RU) operated by multiple O-DU nodes can provide support for enhanced functionality when using lower layer splits in O-RAN in both single and multiple operator deployments. For example, a shared O-RU can support increased scalability and / or increased availability and / or enable access-specific node deployments in the fronthaul system, where multiple O-DU nodes are deployed by a single operator and connected to a shared O-RU. Furthermore, a shared O-RU can support enhanced sharing functionality where multiple O-DU nodes are deployed by different operators and connected to a common shared O-RU node.
[0007] Some example use cases of such O-RU sharing, where a common O-RU serves multiple O-DUs, include the following: RAN Sharing - Use Cases of Multi-Operator Radio Access Network (MORAN) in O-RAN Use cases for multi-vendor slicing in O-RAN. Shared ORU-regulatory requirements for ultra-rural areas often force operators to provide coverage in sparsely populated areas that are not attractive for business or have high subscriber counts, creating profitability issues.
[0008] To this end, RAN sharing is a promising solution for reducing network costs and increasing network capacity and coverage while improving customer satisfaction. However, there is no clear mechanism for establishing secure connections between a common O-RU and multiple O-DUs. For example, in the context of a common O-RU operating with multiple O-DUs in a multi-operator deployment, there is a lack of trust exchange between operators. Current certificate management for O-RUs is handled by an operator certificate authority (CA), where the operator owns the O-RUs operated by a single O-DU. Therefore, certificate management for shared O-RU use cases, such as MORAN, vendor slicing, and rural uses, remains unresolved. Summary of the Invention [Means for solving the problem]
[0009] According to embodiments, a system and method are provided for establishing trust between multiple operators sharing a common O-RU and for handling certificate management for the common O-RU.
[0010] According to embodiments, systems and methods provide an O-RAN public key infrastructure (PKI) service provider to issue certificates to common or shared O-RUs, allowing multiple operators to establish trust relationships and thereby providing a certificate management solution for shared O-RU use cases such as MORAN, vendor slicing, rural use, etc. As a result, Mobile Network Operators (MNOs) can authenticate shared O-RUs using certificates issued by the O-RAN PKI service provider and extend their network coverage (e.g., to rural areas) at low cost.
[0011] According to one aspect of an example embodiment, a first network node of a first of a plurality of mobile network operators (MNOs) includes a memory that stores instructions and at least one processor configured to execute the instructions to receive a digital certificate issued to the first network node from a public key infrastructure (PKI) service provider, the PKI service provider having a trust relationship with the plurality of MNOs; establish a secure connection with a second network node of the first MNO using the issued digital certificate by the first network node based on the trust relationship; and establish a secure connection with a third network node of a second MNO of the plurality of MNOs using the issued digital certificate by the first network node based on the trust relationship.
[0012] The first network node may be a radio unit (RU) of the first MNO, the second network node may be a distributed unit (DU) of the first MNO, and the third network node may be a DU of the second MNO.
[0013] The RU may be a 4G or 5G RU configured with functional radio access network (RAN) division.
[0014] The RU may be an Open RAN (O-RAN) RU (O-RU), and the DU of the first MNO and the DU of the second MNO may be O-RAN DUs (O-DUs).
[0015] The first network node may be a base station of the first MNO, the second network node may be a core network node of the first MNO, and the third network node may be a core network node of the second MNO.
[0016] The at least one processor may be configured to execute instructions to receive a digital certificate according to the EST protocol or the Certificate Management protocol.
[0017] The at least one processor can be configured to execute instructions to send a certificate signing request (CSR) to a PKI service provider and receive a digital certificate based on the sent CSR.
[0018] According to one aspect of an example embodiment, a method for providing a secure connection between a shared network node and multiple network nodes of different mobile network operators (MNOs) includes receiving, by a first network node of a first one of the different MNOs, a digital certificate issued to the first network node from a public key infrastructure (PKI) service provider, the PKI service provider having a trust relationship with the different MNO; establishing a secure connection with a second network node of the first MNO using the issued digital certificate by the first network node based on the trust relationship; and establishing a secure connection with a third network node of a second one of the different MNOs using the issued digital certificate by the first network node based on the trust relationship.
[0019] The first network node may be a radio unit (RU) of the first MNO, the second network node may be a distributed unit (DU) of the first MNO, and the third network node may be a DU of the second MNO.
[0020] The RU may be a 4G or 5G RU configured with functional radio access network (RAN) division.
[0021] The RU may be an Open RAN (O-RAN) RU (O-RU), and the DU of the first MNO and the DU of the second MNO may be O-RAN DUs (O-DUs).
[0022] The first network node may be a base station of the first MNO, the second network node may be a core network node of the first MNO, and the third network node may be a core network node of the second MNO.
[0023] Receiving the digital certificate may include receiving the digital certificate according to an EST protocol or a certificate management protocol.
[0024] Receiving a digital certificate may include sending a certificate signing request (CSR) to a PKI service provider and receiving a digital certificate based on the sent CSR.
[0025] According to one aspect of an example embodiment, a non-transitory computer-readable storage medium has stored thereon instructions executable by at least one processor of a first network node to perform a method for providing secure connections with multiple network nodes of different mobile network operators (MNOs), the method including receiving, by a first network node of a first one of the different MNOs, a digital certificate issued to the first network node from a public key infrastructure (PKI) service provider, the PKI service provider having a trust relationship with the different MNO; establishing a secure connection with a second network node of the first MNO using the digital certificate issued by the first network node based on the trust relationship; and establishing a secure connection with a third network node of a second one of the different MNOs using the digital certificate issued by the first network node based on the trust relationship.
[0026] The first network node may be a radio unit (RU) of the first MNO, the second network node may be a distributed unit (DU) of the first MNO, and the third network node may be a DU of the second MNO.
[0027] The RU may be a 4G or 5G RU configured with functional radio access network (RAN) division.
[0028] The RU may be an Open RAN (O-RAN) RU (O-RU), and the DU of the first MNO and the DU of the second MNO may be O-RAN DUs (O-DUs).
[0029] The first network node may be a base station of the first MNO, the second network node may be a core network node of the first MNO, and the third network node may be a core network node of the second MNO.
[0030] Receiving the digital certificate may include receiving the digital certificate according to an EST protocol or a certificate management protocol.
[0031] Additional aspects will be set forth in part in the description that follows, and in part will be apparent from the description, or may be learned by practice of the illustrated embodiments of the present disclosure. [Brief explanation of the drawings]
[0032] Features of exemplary embodiments of the present disclosure are described below with reference to the accompanying drawings, in which like reference numerals refer to like elements.
[0033] [Figure 1] FIG. 1 is a block diagram illustrating a Radio Access Network (RAN) sharing use case for a Multi-Operator Radio Access Network (MORAN), according to one embodiment. [Figure 2] 1 is a flow diagram of a method for registering a certificate for a shared O-RU according to one embodiment. [Figure 3] FIG. 10 is a block diagram illustrating a RAN sharing use case for MORAN according to another embodiment. [Figure 4] FIG. 10 is a flow diagram of a method for registering a certificate for a shared O-RU according to another embodiment. [Figure 5] FIG. 10 is a block diagram illustrating a RAN sharing use case for MORAN according to another embodiment. [Figure 6] FIG. 10 is a flow diagram of a method for registering a certificate for a shared O-RU according to another embodiment. [Figure 7] FIG. 10 is a block diagram illustrating a RAN sharing use case for MORAN according to another embodiment. [Figure 8] FIG. 10 is a flow diagram of a method for registering a certificate for a shared O-RU according to another embodiment. [Figure 9] FIG. 10 is a block diagram illustrating a RAN sharing use case for MORAN according to another embodiment. [Figure 10] FIG. 10 is a flow diagram of a method for registering a certificate for a shared O-RU according to another embodiment. [Figure 11] FIG. 1 is a block diagram illustrating a RAN sharing use case for rural areas, according to one embodiment. [Figure 12] FIG. 10 is a block diagram illustrating a RAN sharing use case for rural areas according to another embodiment. [Figure 13] 1 is a flowchart of a method for establishing a secure connection between a common radio unit (RU) and multiple distributed units sharing the common RU, according to one or more embodiments. [Figure 14] FIG. 1 is a diagram of components of one or more devices, according to an exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0034] The following detailed description of the exemplary embodiments refers to the accompanying drawings, in which the same reference numbers in different drawings may identify the same or similar elements.
[0035] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit implementations to the precise form disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practice of implementations. Moreover, one or more features or components of one embodiment may be incorporated into or combined with another embodiment (or one or more features of another embodiment). Furthermore, in the flowcharts and descriptions of operations provided below, it is understood that one or more operations may be omitted, one or more operations may be added, one or more operations may be performed (at least partially) concurrently, and the order of one or more operations may be permuted.
[0036] It will be apparent that the systems and / or methods described herein may be implemented in various forms of hardware, firmware, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not intended to limit the implementation. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code. It will be understood that software and hardware can be designed to implement the systems and / or methods based on the description herein.
[0037] Although particular combinations of features are recited in the claims and / or disclosed herein, these combinations are not intended to limit the disclosure of possible implementations. Indeed, many of these features may be combined in ways not specifically recited in the claims and / or disclosed herein. Although each dependent claim listed below may depend directly on only one claim, the disclosure of possible implementations includes each dependent claim in combination with every other claim in the claim set.
[0038] No element, act, or instruction used herein should be construed as critical or essential unless explicitly stated as such. Additionally, as used herein, the articles "a" and "an" are intended to include one or more items and may be used interchangeably with "one or more." Where only one item is intended, the term "one" or similar language is used. Furthermore, as used herein, terms such as "has," "have," "having," "include," and "including" are intended to be open-ended terms. Furthermore, the phrase "based on" is intended to mean "based at least in part on," unless specifically stated otherwise. Furthermore, phrases such as "at least one of [A] and [B]" and "at least one of [A] or [B]" should be understood to include A only, B only, or both A and B.
[0039] Exemplary embodiments of the present disclosure provide a method and system in which a trust exchange is established with multiple mobile network operators (MNOs) that share a common O-RU, and certificate management is provided for the common O-RU, thereby providing secure communications for the MNOs that share the O-RU, thereby enabling the MNOs to obtain the benefits of the shared O-RU (e.g., expanded mobile network coverage at lower cost).
[0040] Additionally, exemplary embodiments provide an O-RAN PKI service provider to manage certificate enrollment, with multiple MNOs having an established trust relationship with the O-RAN PKI service provider. As a result, the MNOs can authenticate shared O-RUs using certificates issued by the O-RAN PKI service provider, enabling them to extend network coverage (e.g., to rural areas) at low cost. In some exemplary embodiments, the O-RAN PKI service provider can serve a single operator in the context of a multiple O-DU to one O-RU use case to gain the benefit of easier certificate enrollment.
[0041] Figure 1 is a block diagram illustrating a radio access network (RAN) sharing use case for a multi-operator radio access network (MORAN), according to one embodiment. Referring to Figure 1, an O-RAN PKI service provider establishes trust relationships with multiple operators and issues certificates to the shared O-RU. The O-RAN PKI service provider may be any publicly available certificate authority (CA). The multiple operators (Operator 1 and Operator 2) sharing the O-RU trust the certificates issued by the O-RAN PKI service provider because the multiple operators have already established trust relationships with the O-RAN PKI service provider.
[0042] According to one or more embodiments, the O-RAN PKI service provider satisfies all technical requirements of the MNO's network, such as O-RAN acceptable cryptography standards, Certificate Management Protocol (CMP), registration mechanisms such as EST / ACME, and open fronthaul flows for certificate registration, as well as shared trust between two or more O-RAN operators or Shared O-RAN operators (SOROs).
[0043] Figure 2 is a flow diagram of a method for registering a certificate for a shared O-RU 210, according to one embodiment. For example, the method illustrated in Figure 2 may be applied to certificate registration for the shared O-RU shown in Figure 1. While an O-RU is illustrated as a shared network element and a network element to which a certificate is issued by a PKI service provider, it will be understood that one or more other embodiments are not limited thereto and may be applied to other types of network elements.
[0044] 2, the shared O-RU 210 has installed therein a private key and the shared O-RU's Certificate Authority (CA) certificate (e.g., a certificate issued by the O-RU's vendor CA or the CA of the O-RU operator (i.e., the MNO that owns the O-RU)). The O-RAN PKI service provider 220, according to an example embodiment, also installs the shared O-RU's CA certificate.
[0045] In operation S201, the shared O-RU 210 generates a certificate signing request (CSR). For example, the CSR may be formatted according to a predefined standard such as Public Key Cryptography Standards (PKCS) 10.
[0046] In operations S202 and S203, the shared O-RU 210 sends the CSR to the O-RAN PKI service provider 220. To this end, the certificate request may conform to a predefined protocol such as the Enrollment over Secure Transport (EST) protocol (i.e., as defined in RFC 7030), the Simple Certificate Enrollment Protocol (SCEP), the Certificate Management Protocol (CMP), or the Certificate Management over Cryptographic Message Syntax (CMC).
[0047] In operation S204, if the authentication is successful (e.g., using the CA certificate of the shared O-RU), the O-RAN PKI service provider 220 issues a certificate, which is sent to the shared O-RU 210 in operations S205 and S206.
[0048] Figure 3 is a block diagram illustrating a RAN sharing use case for MORAN according to another embodiment. Referring to Figure 3, an O-RAN PKI service provider establishes trust relationships with multiple operators and issues certificates to an intermediate CA of one of the operators. The O-RAN PKI service provider may be any publicly available certificate authority (CA). In the embodiment of Figure 3, the shared O-RU enrolls with Operator 1's intermediate CA, and the O-RAN PKI service provider is the root CA of the shared O-RU. The multiple operators (Operator 1 and Operator 2) sharing the O-RU trust the certificate issued by the intermediate CA and therefore trust the root certificate because the multiple operators have already established trust relationships with the root CA, i.e., the O-RAN PKI service provider.
[0049] 4 is a flow diagram of a method for registering a certificate for a shared O-RU according to another embodiment. For example, the method illustrated in FIG. 4 may be applied to certificate registration for the shared O-RU shown in FIG. 3. Although an O-RU is illustrated as a shared network element and a network element to which a certificate is issued by a PKI service provider, it will be understood that one or more other embodiments are not limited thereto and may be applied to other types of network elements.
[0050] 4, the shared O-RU 410 has installed therein a private key and the certificate authority (CA) certificate of the shared O-RU (e.g., a certificate issued by the vendor CA of the O-RU or the CA of the O-RU operator (i.e., the MNO that owns the O-RU)). The certificate authority of Operator 1 (e.g., EST server 430 and / or intermediate CA 440) also has installed therein the CA certificate of the shared O-RU. After authentication, the shared O-RU 410 obtains the intermediate CA chain certificate of Operator 1.
[0051] Specifically, in operation S401, the shared O-RU 410 generates a certificate signing request (CSR). For example, the CSR may be formatted according to a predefined standard, such as Public Key Cryptography Standard (PKCS) 10.
[0052] In operations S402 and S403, the shared O-RU 410 sends the CSR to the certification authority of Operator 1. To this end, the certificate request may conform to a predefined protocol such as the Enrollment over Secure Transport (EST) protocol (i.e., as defined in RFC 7030), although other embodiments are not limited thereto and may apply other protocols (e.g., Simple Certificate Enrollment Protocol (SCEP), Certificate Management Protocol (CMP), Certificate Management via Cryptographic Message Syntax (CMC), etc.).
[0053] In operation S404, if authentication is successful (eg, using the CA certificate of the shared O-RU), the intermediate CA 440 issues a certificate, which is sent to the shared O-RU 410 in operations S405 and S406.
[0054] Figure 5 is a block diagram illustrating a RAN sharing use case for MORAN according to another embodiment. Referring to Figure 5, an O-RAN PKI service provider establishes trust relationships with multiple operators and issues certificates to an intermediate CA of one of the operators. The O-RAN PKI service provider may be any publicly available certificate authority (CA). In the embodiment of Figure 5, the shared O-RU enrolls with Operator 1's intermediate CA through Operator 1's Service Management and Orchestration (SMO) platform, which is the trust anchor. The O-RAN PKI service provider is the root CA of the shared O-RU, and the SMO enrolls with the external O-RAN PKI service provider. The multiple operators (Operator 1 and Operator 2) sharing the O-RU trust the certificate issued by the intermediate CA because the multiple operators have already established trust relationships with the root CA, i.e., the O-RAN PKI service provider, and therefore trust the root certificate.
[0055]
[0023] Figure 6 is a flow diagram of a method for registering a certificate for a shared O-RU according to another embodiment. For example, the method illustrated in Figure 6 may be applied to certificate registration for the shared O-RU shown in Figure 5. Although an O-RU is illustrated as a shared network element and a network element to which a certificate is issued by a PKI service provider, it will be understood that one or more other embodiments are not limited thereto and may be applied to other types of network elements.
[0056] 6, the shared O-RU 610 has installed therein a private key and the certificate authority (CA) certificate of the shared O-RU (e.g., a certificate issued by the vendor CA of the O-RU or the CA of the O-RU operator (i.e., the MNO that owns the O-RU)). The certificate authority of Operator 1 (e.g., intermediate CA 640 in Operator 1's SMO 630) also has installed therein the CA certificate of the shared O-RU. The shared O-RU 610 obtains the intermediate CA certificate of Operator 1 after authentication.
[0057] Specifically, in operation S601, the shared O-RU 610 generates a certificate signing request (CSR). For example, the CSR may be formatted according to a predefined standard, such as Public Key Cryptography Standard (PKCS) 10.
[0058] In operation S602, the shared O-RU 610 sends the CSR to the certification authority of Operator 1. To this end, the certificate request may conform to a predefined protocol such as EST, Simple Certificate Enrollment Protocol (SCEP), Certificate Management Protocol (CMP), Certificate Management via Cryptographic Message Syntax (CMC), etc.
[0059] In operation S603, if the authentication is successful (eg, using the CA certificate of the shared O-RU), the intermediate CA 640 issues a certificate, which is sent to the shared O-RU 610 in operation S604.
[0060] Figure 7 is a block diagram illustrating a RAN sharing use case for MORAN according to another embodiment. Referring to Figure 7, an O-RAN PKI service provider establishes trust relationships with multiple operators and issues certificates to an intermediate CA of one of the operators. The O-RAN PKI service provider may be any publicly available certificate authority (CA). In the embodiment of Figure 7, the shared O-RU enrolls with Operator 1's intermediate CA through Operator 1's O-DU, which is the trust anchor. The O-RAN PKI service provider is the root CA of the shared O-RU, and the O-DU enrolls with the external O-RAN PKI service provider. The multiple operators (Operator 1 and Operator 2) sharing the O-RU trust the certificate issued by the intermediate CA because the multiple operators have already established trust relationships with the root CA, i.e., the O-RAN PKI service provider, and therefore trust the root certificate.
[0061]
[0023] Figure 8 is a flow diagram of a method for registering a certificate for a shared O-RU according to another embodiment. For example, the method illustrated in Figure 8 may be applied to the certificate registration for the shared O-RU illustrated in Figure 7. Although an O-RU is illustrated as a shared network element and a network element to which a certificate is issued by a PKI service provider, it will be understood that one or more other embodiments are not limited thereto and may be applied to other types of network elements.
[0062] 8, the shared O-RU 810 has installed therein a private key and the certificate authority (CA) certificate of the shared O-RU (e.g., a certificate issued by the vendor CA of the O-RU or the CA of the O-RU operator (i.e., the MNO that owns the O-RU)). The certificate authority of Operator 1 (e.g., intermediate CA 840 in Operator 1's O-DU 830) also has installed therein the CA certificate of the shared O-RU. The shared O-RU 810 obtains the intermediate CA certificate of Operator 1 after authentication.
[0063] Specifically, in operation S801, the shared O-RU 810 generates a certificate signing request (CSR). For example, the CSR may be formatted according to a predefined standard such as Public Key Cryptography Standard (PKCS) 10.
[0064] In operation S802, the shared O-RU 810 sends the CSR to the certification authority of Operator 1. To this end, the certificate request may conform to a predefined protocol such as EST, Simple Certificate Enrollment Protocol (SCEP), Certificate Management Protocol (CMP), Certificate Management via Cryptographic Message Syntax (CMC), etc.
[0065] In operation S803, if the authentication is successful (eg, using the CA certificate of the shared O-RU), the intermediate CA 840 issues a certificate, which is sent to the shared O-RU 810 in operation S804.
[0066] 9 is a block diagram illustrating a RAN sharing use case for MORAN according to another embodiment. Referring to FIG. 9, a second operator (Operator 2) has an established trust relationship with a root CA of a first operator (Operator 1). As a result, a shared O-RU can register with an intermediate CA of Operator 1, which registers with the root CA of Operator 1.
[0067] Figure 10 is a flow diagram of a method for registering a certificate for a shared O-RU according to another embodiment. For example, the method illustrated in Figure 10 may be applied to the certificate registration for the shared O-RU shown in Figure 9. Although an O-RU is illustrated as a shared network element and a network element to which a certificate is issued by a PKI service provider, it will be understood that one or more other embodiments are not limited thereto and may be applied to other types of network elements.
[0068] 10, the shared O-RU 1010 has installed therein a private key and the certificate authority (CA) certificate of the shared O-RU (e.g., a certificate issued by the vendor CA of the O-RU or the CA of the O-RU operator (i.e., the MNO that owns the O-RU)). The certificate authority of Operator 1 (e.g., an intermediate CA 1040 that registers a certificate with Operator 1's root CA 1030) also has installed therein the CA certificate of the shared O-RU. The shared O-RU 1010 obtains the intermediate CA certificate of Operator 1 after authentication.
[0069] Specifically, in operation S1001, the shared O-RU 810 generates a certificate signing request (CSR). For example, the CSR may be formatted according to a predefined standard, such as Public Key Cryptography Standard (PKCS) 10.
[0070] In operation S1002, the shared O-RU 1010 sends the CSR to the certification authority of Operator 1. To this end, the certificate request may conform to a predefined protocol such as EST, Simple Certificate Enrollment Protocol (SCEP), Certificate Management Protocol (CMP), Certificate Management via Cryptographic Message Syntax (CMC), etc.
[0071] In operation S1003, if the authentication is successful (eg, using the CA certificate of the shared O-RU), the intermediate CA 1040 issues a certificate, which is sent to the shared O-RU 1010 in operation S1004.
[0072] Figure 11 is a block diagram illustrating a RAN sharing use case for rural areas, according to one embodiment. The embodiment of Figure 11 is directed to a non-segmented 4G eNB architecture, although it will be appreciated that one or more other embodiments may be applied to non-segmented 5G architectures, O-RAN architectures, etc.
[0073] Referring to FIG. 11 , both a 4G base station (eNB) located in rural area site A and owned by Operator X and a 4G eNB located in rural site B and owned by Operator Y are provisioned with certificates from an O-RAN PKI service provider according to one or more embodiments. As described above, both operators have established trust relationships with the O-RAN PKI service provider. Therefore, secure connections between each eNB and both operators can be established using the certificates issued by the O-RAN PKI service provider. Thus, Operator X's eNB can be shared by both Operator X and Operator Y (i.e., connected to Operator X's core network and Operator Y's core network), and Operator Y's eNB can be shared by both Operator X and Operator Y (i.e., connected to Operator X's core network and Operator Y's core network). As a result, Operator Y can provide subscriber access and connectivity in rural area site A without having to deploy its own base station, thus saving resources and costs and expanding its network coverage. Similarly, Operator X may offer similar benefits to subscriber access and connectivity at rural area site B.
[0074] 12 is a block diagram illustrating a RAN sharing use case for rural areas, according to another embodiment. The embodiment of FIG. 12 relates to a split 4G eNB and / or 5G gNB architecture. For example, a base station may be configured with functionality split option 7.2x, although this is merely an example and one or more other exemplary embodiments are not limited thereto.
[0075] 12 , an O-RU (4G or 5G) located in rural area site A and owned by Operator X and an O-RU (4G or 5G) located in rural site B and owned by Operator Y are both provisioned with certificates from an O-RAN PKI service provider according to one or more embodiments. As described above, both operators have established trust relationships with the O-RAN PKI service provider. Therefore, secure connections between each O-RU and both operators can be established using certificates issued by the O-RAN PKI service provider. Therefore, Operator X's O-RU can be shared by both Operator X and Operator Y (i.e., connected to Operator X's O-DU and Operator Y's O-DU), and Operator Y's O-RU can be shared by both Operator X and Operator Y (i.e., connected to Operator X's O-DU and Operator Y's O-DU). As a result, Operator Y can provide access and connectivity for subscribers at rural area site A without having to deploy its own base stations or radio units, thus saving resources and costs and extending its network coverage. Similarly, Operator X can provide similar benefits for subscriber access and connectivity at rural area site B.
[0076] 13 is a flowchart of a method for establishing a secure connection between a common RU and multiple DUs sharing the common RU, according to one or more embodiments. According to one or more embodiments, the RU and multiple DUs may be based on O-RAN technology (i.e., O-RU and O-DU) and may be connected via O-RAN open fronthaul interfaces and specifications, although it is understood that one or more other embodiments are not limited thereto. For example, one or more other embodiments may share network elements such as base stations without functional splitting (i.e., split architecture).
[0077] Referring to FIG. 13 , in operation S1310, an RU of a first mobile network operator (MNO) receives a certificate issued to the RU from a PKI service provider according to an exemplary embodiment. The PKI server has established trust relationships with multiple MNOs, including the first MNO. For example, nodes (e.g., O-DUs) of the multiple MNOs may internally store the root certificate of the PKI service provider or may have established or registered the PKI service provider as a trusted entity. The O-RU may request and register a certificate according to a specific protocol, such as the Enrollment over Secure Transport (EST) protocol (i.e., as defined in RFC 7030), the Simple Certificate Enrollment Protocol (SCEP), CMP, or Certificate Management over Cryptographic Message Syntax (CMC). Furthermore, the O-RU may generate and submit a Certificate Signing Request (CSR), and the PKI service provider may issue a certificate based on the CSR. The certificate may be formatted according to a predefined standard, such as X.509.
[0078] At operation S1320, the RU uses the issued certificate to establish a secure connection with the DU of the first MNO based on the established trust between the second MNO and the PKI service provider. For example, the RU may be authenticated by the DU of the first MNO by sending its certificate according to an authentication procedure (e.g., a predefined authentication procedure).
[0079] At operation S1330, the RU uses the issued certificate to establish a secure connection with a DU of a second MNO of the multiple MNOs based on the established trust between the second MNO and the PKI service provider. For example, the RU may be authenticated by the DU of the second MNO by sending its certificate in accordance with an authentication procedure (e.g., a predefined authentication procedure).
[0080] Because there is a trust relationship between the PKI service provider (e.g., a certificate authority) and both MNOs, a secure connection between the shared RU and the DUs of both MNOs can be established using certificates issued by the PKI service provider.
[0081] 14 is a diagram of components of one or more devices, according to an example embodiment. The device 1400 may correspond to any of the devices described above (e.g., network elements (RU, DU, gNB, eNB, core network element, CA, intermediate CA, PKI service provider, etc.)).
[0082] 14, device 1400 may include a bus 1410, a processor 1420, a memory 1430, a storage component 1440, and a communication interface 1450. It will be understood that one or more of the components may be omitted and / or one or more additional components may be included.
[0083] The bus 1410 includes components that enable communication between the components of the device 1400. The processor 1420 is implemented in hardware, firmware, or a combination of hardware and software. The processor 1420 may be a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), a microprocessor, a microcontroller, a digital signal processor (DSP), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), or another type of processing component. The processor 1420 includes one or more processors that can be programmed to perform functions.
[0084] Memory 1430 may include random access memory (RAM), read-only memory (ROM), and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, and / or optical memory) that stores information and / or instructions for use by processor 1420.
[0085] Storage component 1440 stores information and / or software related to the operation and use of device 1400. For example, storage component 1440 may include a hard disk (e.g., a magnetic disk, optical disk, magneto-optical disk, and / or solid-state disk), a compact disk (CD), a digital versatile disk (DVD), a floppy disk, a cartridge, a magnetic tape, and / or another type of non-transitory computer-readable medium along with a corresponding drive.
[0086] Communications interface 1450 includes transceiver-like components (e.g., a transceiver and / or a separate receiver and transmitter) that enable device 1400 to communicate with other devices via wired connections, wireless connections, or a combination of wired and wireless connections, etc. Communications interface 1450 may enable device 1400 to receive information from and / or provide information to another device. For example, communications interface 1450 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi interface, a cellular network interface, etc.
[0087] Device 1400 may perform one or more processes or functions described herein. Device 1400 may perform operations based on processor 1420 executing software instructions stored by a non-transitory computer-readable medium, such as memory 1430 and / or storage component 1440. A computer-readable medium is defined herein as a non-transitory memory device. A memory device includes memory space within a single physical storage device or memory space across multiple physical storage devices.
[0088] The software instructions may be loaded into memory 1430 and / or storage component 1440 from another computer-readable medium or from another device via communications interface 1450. When executed, the software instructions stored in memory 1430 and / or storage component 1440 may cause processor 1420 to perform one or more processes described herein.
[0089] While the above-described example embodiments relate to an O-RU as a shared network element, it will be appreciated that one or more other embodiments are not limited thereto and are applicable to any network element (e.g., eNB, gNB, transport element, etc.) that may be shared between operators (i.e., shared by respective network elements (e.g., DUs, core network elements, etc.) of multiple operators).
[0090] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the implementations to the precise forms disclosed. Modifications and variations are possible in light of the above disclosure or may be acquired from practicing the implementations.
[0091] Some embodiments may relate to systems, methods, and / or computer-readable media at any possible level of technical detail regarding integration. Furthermore, one or more of the above components described above may be implemented as instructions stored on a computer-readable medium and executable by at least one processor (and / or may include at least one processor). The computer-readable medium may include a computer-readable non-transitory storage medium having computer-readable program instructions for causing a processor to perform operations.
[0092] A computer-readable storage medium may be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory stick, floppy disk, mechanically encoded devices such as punch cards or groove ridge structures having instructions recorded therein, and any suitable combination thereof. As used herein, computer-readable storage media should not be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses passing through a fiber optic cable), or electrical signals transmitted through electrical wires.
[0093] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface within each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing device.
[0094] The computer-readable program code / instructions for carrying out operations may be either source code or object code written in any combination of one or more programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or object-oriented programming languages such as Smalltalk, C++, and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., over the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer-readable program instructions and personalize the electronic circuitry by utilizing state information of the computer-readable program instructions to perform aspects or operations.
[0095] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, executing via the processor of the computer or other programmable data processing apparatus, create means for performing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. These computer-readable program instructions may also be stored on a computer-readable storage medium that can direct a computer, programmable data processing apparatus, and / or other device to function in a particular manner, such that a computer-readable storage medium having instructions stored therein comprises an article of manufacture containing instructions that implement aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0096] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device and cause the computer, other programmable apparatus, or other device to perform a series of operational steps to create a computer-implemented process, such that the instructions executing on the computer, other programmable apparatus, or other device perform the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.
[0097] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer-readable media according to various embodiments. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing the specified logical function(s). The methods, computer systems, and computer-readable media may include more, fewer, different, or differently arranged blocks than those shown in the figures. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may actually be executed concurrently or substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block in the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, can be implemented by dedicated hardware-based systems that perform the specified functions or operations, or that execute a combination of dedicated hardware and computer instructions.
[0098] It will be apparent that the systems and / or methods described herein may be implemented in various forms of hardware, firmware, or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not intended to limit the implementation. Thus, the operation and behavior of the systems and / or methods are described herein without reference to specific software code, and it will be understood that software and hardware can be designed to implement the systems and / or methods based on the description herein.
Claims
1. a first network node of a first of a plurality of mobile network operators (MNOs), the first network node comprising: a memory for storing instructions; Execute the instructions, Sending a Certificate Signing Request (CSR) to a Public Key Infrastructure (PKI) service provider; receiving a common digital certificate issued to the first network node in response to transmitting the CSR to the PKI service provider, the common digital certificate having a chain of trust to the PKI service provider indicating that the PKI service provider has a trust relationship with each of the plurality of MNOs; establishing, by the first network node, a secure connection with a second network node of the first MNO using the common digital certificate and based on the chain of trust indicating a trust relationship between the first MNO and the PKI service provider; establishing, by the first network node, a secure connection with a third network node of the second MNO using the common digital certificate based on the chain of trust indicating a trust relationship between a second MNO of the plurality of MNOs and the PKI service provider; at least one processor configured to Equipped with A first network node, wherein the first network node is a radio unit (RU) of the first MNO, the second network node is a distributed unit (DU) of the first MNO, and the third network node is a DU of the second MNO.
2. The first network node of claim 1 , wherein the RU is a 4G or 5G RU configured with functional radio access network (RAN) division.
3. The first network node of claim 1 , wherein the RU is an Open RAN (O-RAN) RU (O-RU), and the DU of the first MNO and the DU of the second MNO are O-RAN DUs (O-DUs).
4. The at least one processor executes the instructions to Sending the CSR to an intermediate Certificate Authority (CA) of the first MNO; The first network node of claim 1 , configured to receive the digital certificate from the intermediate CA in response to transmitting the CSR to the intermediate CA.
5. The first network node of claim 4 , wherein the intermediate CA is located within a Service Management and Orchestration (SMO) platform of the first MNO or an O-DU of the first MNO.
6. 1. A method for providing secure connectivity between a shared network node and multiple network nodes of different mobile network operators (MNOs), the method comprising: sending, by a first network node of a first one of the different MNOs, a certificate signing request (CSR) to a public key infrastructure (PKI) service provider; receiving a common digital certificate issued to the first network node in response to transmitting the CSR to the PKI service provider by the first network node, the common digital certificate having a chain of trust to the PKI service provider indicating that the PKI service provider has a trust relationship with each of the different MNOs; establishing, by the first network node, a secure connection with a second network node of the first MNO using the common digital certificate and based on the chain of trust indicating a trust relationship between the first MNO and the PKI service provider; establishing, by the first network node, a secure connection with a third network node of the second one of the different MNOs using the common digital certificate and based on the chain of trust indicating a trust relationship between the second one of the different MNOs and the PKI service provider; Including, 1. The method of claim 1, wherein the first network node is a radio unit (RU) of the first MNO, the second network node is a distributed unit (DU) of the first MNO, and the third network node is a DU of the second MNO.
7. The method of claim 6 , wherein the RU is a 4G or 5G RU configured with functional radio access network (RAN) splitting.
8. The method of claim 6, wherein the RU is an Open RAN (O-RAN) RU (O-RU), and the DU of the first MNO and the DU of the second MNO are O-RAN DUs (O-DUs).
9. Transmitting the CSR includes transmitting the CSR to an intermediate certificate authority (CA) of the first MNO; The method of claim 6 , wherein receiving the digital certificate comprises receiving the digital certificate from the intermediate CA.
10. The method of claim 9, wherein the intermediate CA is located within a Service Management and Orchestration (SMO) platform of the first MNO or an O-DU of the first MNO.
11. 1. A non-transitory computer-readable storage medium having instructions executable by at least one processor of a first network node to perform a method for providing secure connectivity with multiple network nodes of different mobile network operators (MNOs), the method comprising: sending, by a first network node of a first one of the different MNOs, a certificate signing request (CSR) to a public key infrastructure (PKI) service provider; receiving a common digital certificate issued to the first network node in response to transmitting the CSR to the PKI service provider by the first network node, the common digital certificate having a chain of trust to the PKI service provider indicating that the PKI service provider has a trust relationship with each of the different MNOs; establishing, by the first network node, a secure connection with a second network node of the first MNO using the common digital certificate and based on the chain of trust indicating a trust relationship between the first MNO and the PKI service provider; establishing, by the first network node, a secure connection with a third network node of the second one of the different MNOs using the common digital certificate and based on the chain of trust indicating a trust relationship between the second one of the different MNOs and the PKI service provider; Including, 1. A non-transitory computer-readable storage medium, wherein the first network node is a radio unit (RU) of the first MNO, the second network node is a distributed unit (DU) of the first MNO, and the third network node is a DU of the second MNO.
12. 12. The non-transitory computer-readable storage medium of claim 11, wherein the RU is a 4G or 5G RU configured with functional radio access network (RAN) splitting.
13. 12. The non-transitory computer-readable storage medium of claim 11, wherein the RU is an Open RAN (O-RAN) RU (O-RU), and the DU of the first MNO and the DU of the second MNO are O-RAN DUs (O-DUs).
14. The method of claim 13, wherein transmitting the CSR includes transmitting the CSR to an intermediate certificate authority (CA) of the first MNO; 12. The non-transitory computer-readable medium of claim 11, wherein receiving the digital certificate comprises receiving the digital certificate from the intermediate CA.
Citation Information
Patent Citations
Radio base station device, radio base station program, and radio communication system
JP2021190805A
Method and system for controlling UICC and euicc
US20190208405A1
Remote Provision Of A Subscriber Entity
US20190313241A1