Cell site management in a radio access network

Automated configuration and software management of cell site nodes using pre-installed certificates and central server updates address the inefficiencies of manual configuration, improving network performance and security by reducing bandwidth reliance and enhancing cloud infrastructure operation.

JP7828513B2Active Publication Date: 2026-03-11RAKUTEN SYMPHONY INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-10-03
Publication Date
2026-03-11

AI Technical Summary

Technical Problem

Cell sites in wireless communication networks require manual configuration and software updates, which are time-consuming and costly due to the large number of unstaffed sites, leading to potential communication slowdowns and resource wastage.

Method used

A method for configuring cell site nodes using pre-installed certificates and software updates, enabling automatic configuration and software management through a central server, allowing devices to operate a cloud infrastructure and reduce reliance on remote network bandwidth.

Benefits of technology

Enables efficient, automated configuration and software management of cell site nodes, reducing network bandwidth usage and improving security by running cloud applications locally, thus enhancing network functionality and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007828513000001
    Figure 0007828513000001
  • Figure 0007828513000002
    Figure 0007828513000002
  • Figure 0007828513000003
    Figure 0007828513000003
Patent Text Reader

Abstract

Generally, the subject matter of this disclosure relates to managing cell sites in a Radio Access Network (RAN), such as an Open RAN (O-RAN). In some implementations, managing a cell site in the RAN may include transmitting a first certificate pre-installed in the cell site node from the node to a first server in a wireless communication system, receiving a second certificate at the node from the first server after transmitting the first certificate, transmitting the second certificate from the node to a central server, and receiving configuration information at the node from the central server after transmitting the second certificate. The configuration information may indicate a configuration of the node for communication in the wireless communication system. Upon receiving the configuration information, the node may use the configuration information to automatically configure itself for communication in the wireless communication system.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] In some implementations, the subject matter of this disclosure relates to telecommunications systems, and more particularly to managing cell sites in a Radio Access Network (RAN), such as an Open Radio Access Network (O-RAN). [Background technology]

[0002] In today's world, cellular networks provide on-demand communication capabilities to individuals and businesses. Typically, cellular networks are wireless networks that can be distributed over a terrestrial area called a cell. Each such cell is served by at least one fixed-location transceiver called a cell site or base station. Each cell may use a different set of frequencies from its neighboring cells to avoid interference and provide improved service within each cell. When cells are combined, they provide radio coverage over a wide geographic area, allowing numerous mobile phones and / or other wireless devices or portable transceivers to communicate with each other and with fixed transceivers and phones anywhere in the network. Such communication is conducted through base stations, even if the mobile transceiver is moving through two or more cells during transmission. Major wireless communication providers have deployed such cell sites worldwide, thereby enabling communicating mobile phones and mobile computing devices to connect to the public switched telephone network and the public Internet.

[0003] A mobile phone is a cellular telephone that can make and / or receive phone calls and / or data through a cell site or transmission tower by using radio waves to transfer signals between mobile phones. Given the large number of mobile phone users, current mobile phone networks offer limited shared resources. In that regard, cell sites and handsets can change frequencies and use low-power transmitters to allow simultaneous use of the network by many callers with less interference. Cell site coverage may depend on a particular geographic location and / or the number of users that can potentially use the network. For example, in a city, a cell site may have a range of up to about 1 / 2 mile, while in suburban areas, the range may be as much as 5 miles, and in some areas, users may receive signals from cell sites 25 miles away.

[0004] The following are some examples of digital cellular technologies used by communication providers: Global System for Mobile communications (GSM), General Packet Radio Service (GPRS), cdmaOne, CDMA2000, Evolution-Data Optimized (EV-DO), Enhanced Data rates for GSM Evolution (EDGE), Universal Mobile Telecommunications System (UMTS), Digital Enhanced Cordless Telecommunications (DECT), Digital Advanced Mobile Phone System (AMPS) (IS-136 / Time Division Multiple Access (TDMA)), and Integrated Digital Enhanced Network (iDEN). Long Term Evolution (LTE), also known as 4G Long Term Evolution, developed by the Third Generation Partnership Project (3GPP®) standards organization, is a standard for high-speed data wireless communications for mobile phones and data terminals. 5G standards are currently being developed and deployed. 3GPP cellular technologies such as LTE and 5G New Radio (NR) are an evolution of earlier generations of 3GPP technologies such as GSM / EDGE and UMTS / High Speed ​​Packet Access (HSPA) digital cellular technologies, enabling increased capacity and speeds by using a different air interface along with core network improvements.

[0005] A cellular network can be divided into a radio access network and a core network. The radio access network (RAN) can include network functions capable of handling radio layer communication processing. The core network can include network functions capable of handling higher layer communications, such as Internet Protocol (IP), transport layer, and application layer. In some cases, the RAN functions can be divided into baseband unit functions and radio unit functions, in which case, for example, the radio unit connected to the baseband unit via a fronthaul network can be responsible for lower layer processing of the radio physical layer, while the baseband unit can be responsible for higher layer radio protocols, such as Media Access Control (MAC) and Radio Link Control (RLC).

[0006] Various devices physically located at a cell site need to be configured to initiate communications over the cellular network. Configuring the devices physically located at the cell site can ensure that the devices are authorized to communicate over the cellular network and, therefore, can prevent unauthorized devices from communicating over the cellular network. Unauthorized devices communicating over the cellular network can result in one or more adverse effects, such as interfering with authorized communications, encroaching on bandwidth required for authorized communications, enabling tampering with the cellular network, using cellular network resources without paying for them, and / or causing additional or alternative adverse effects.

[0007] Furthermore, even after a device at a cell site is initially configured, the device may require subsequent configuration, such as for software upgrades or repairs. Upgrading software can be particularly important for devices at cell sites so that they operate optimally while minimizing wasted hardware resources. Because cellular networks typically have a large number of cell sites, communication slowdowns and / or other adverse effects caused by suboptimal software and / or hardware resource wastage can quickly add up across the network.

[0008] However, because the cell sites are not staffed, personnel must travel to perform the initial configuration and any subsequent configuration manually, which is time-consuming and costly, especially since it typically requires visiting multiple cell sites. Summary of the Invention

[0009] In some implementations, the subject matter of this disclosure relates to a computer-implemented method. The method may include transmitting a first certificate pre-installed at a cell site node from the cell site node to a first server in a wireless communication system. The method may also include receiving a second certificate at the cell site node from the first server after transmitting the first certificate. The method may also include transmitting the second certificate from the cell site node to a central server and receiving configuration information at the cell site node from the central server after transmitting the second certificate. The configuration information may indicate a configuration for the cell site node for communication in the wireless communication system. Upon receiving the configuration information, the configuration information may be used to cause the cell site node to automatically configure itself for communication in the wireless communication system.

[0010] In some implementations, the subject matter of this disclosure can include one or more of the following additional features.

[0011] In some implementations, the method may also include transmitting software inventory information from the cell site node to the central server after the cell site node configures itself, and installing updated software at the cell site node in response to the central server determining, based on the software inventory information, that software installed at the cell site node has expired. Furthermore, the central server may be configured to trigger installation of the updated software at any time after the cell site node configures itself. The cell site node may receive installation instructions from the central server in response to the central server determining, based on the software inventory information, that software installed at the cell site node has expired. The installation instructions may cause the cell site node to automatically download the updated software to be installed at the cell site node, and / or the software inventory information may include a manifest listing the respective versions of one or more software modules required by the cell site node. Furthermore, installing the updated software at the cell site node may include downloading software for each of the one or more software modules from the central server and installing the downloaded software on the cell site node.

[0012] In some implementations, the cell site node may transmit software inventory information from the cell site node to the central server to maintain a current software inventory on the cell site node. Furthermore, the software inventory information may include a manifest listing each version of one or more software modules required by the cell site node. The method may further include receiving updated configuration information at the cell site node from the central server after transmitting the software inventory information. The updated configuration information may indicate an updated configuration for at least one software module identified in the software inventory information. Upon receiving the updated configuration information, the cell site node may automatically configure the at least one software module using the updated configuration information. Furthermore, the cell site node transmitting the software inventory information may be triggered by the cell site node initially registering with the central server.

[0013] In some implementations, the first server may transmit the second certificate to the cell site node after the first server approves the first certificate received from the cell site node, and the central server may transmit the configuration information to the cell site node after the central server approves the second certificate received from the cell site node.

[0014] In some implementations, the cell site node receiving the second certificate may automatically trigger the cell site node to transmit the second certificate from the cell site node to the central server.

[0015] In some implementations, an agent pre-installed at the cell site node may cause at least one of transmitting the first certificate, transmitting the second certificate, and the cell site node configuring itself with the configuration information.

[0016] In some implementations, the transmission of the first certificate may be automatically triggered by powering on the cell site node.

[0017] In some implementations, the central server may be configured to update the configuration of a cell site node any time after the cell site node configures itself.

[0018] In some implementations, the cell site node that configures itself may include the cell site node that configures itself to operate a cloud infrastructure locally on the cell site node.

[0019] In some implementations, the wireless communication system may include a Radio Access Network (RAN), which may be an Open RAN (O-RAN).

[0020] In some implementations, the cell site nodes may be in communication with base stations in a wireless communication system. Further, the base stations may include at least one of an eNodeB base station, a gNodeB base station, a wireless base station, and any combination thereof. Further, the base stations may operate in at least one of a Long Term Evolution communication system, a new radio (NR) communication system, and any combination thereof.

[0021] In some implementations, the cell site node may be a distributed unit (DU).

[0022] In some implementations, the central server may be a server of a central management system.

[0023] Non-transitory computer program products (i.e., physically embodied computer program products) are also described, which store instructions that, when executed by one or more data processors of one or more computing systems, cause at least one data processor to perform the operations described herein. Similarly, computer systems are also described, which may include one or more data processors and memory coupled to the one or more data processors. The memory may temporarily or permanently store instructions that cause at least one processor to perform one or more of the operations described herein. Furthermore, the methods may be implemented by one or more data processors, either within a single computing system or distributed among two or more computing systems. Such computing systems may be connected and may exchange data and / or commands or other instructions, etc., via one or more connections, including, but not limited to, connections over a network (e.g., the Internet, a wireless wide area network, a local area network, a wide area network, a wired network, etc.), such as via a direct connection between one or more of the computing systems.

[0024] Details of one or more variations of the subject matter described herein are set forth in the accompanying drawings and the description below. Other features and advantages of the subject matter described herein will be apparent from the description and drawings, and from the claims.

[0025] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate certain aspects of the subject matter disclosed herein and, together with the description, serve to explain some of the principles associated with the disclosed implementations. [Brief explanation of the drawings]

[0026] [Figure 1a]FIG. 1 illustrates an exemplary conventional Long Term Evolution (LTE) communication system.

[0027] [Figure 1b] FIG. 1b illustrates further details of the exemplary LTE system shown in FIG. 1a.

[0028] [Figure 1c] FIG. 1b illustrates further details of the evolved packet core of the exemplary LTE system shown in FIG. 1a.

[0029] [Figure 1d] 1b illustrates an exemplary evolved Node B of the exemplary LTE system shown in FIG. 1a.

[0030] [Figure 2] FIG. 2 is a diagram illustrating further details of the evolved Node B shown in FIGS. 1a to 1d.

[0031] [Figure 3] FIG. 1 illustrates an example virtual radio access network, in accordance with some implementations of the subject matter of this disclosure.

[0032] [Figure 4] FIG. 1 illustrates an exemplary 3GPP split architecture for providing use of higher frequency bands to its users.

[0033] [Figure 5a] FIG. 1 illustrates an exemplary 5G wireless communication system.

[0034] [Figure 5b] A diagram illustrating an example layer architecture of a split gNB and / or a split ng-eNB (e.g., a next-generation eNB connected to 5GC).

[0035] [Figure 5c] FIG. 5B illustrates an exemplary functional split in the gNB architecture shown in FIGS. 5a-5b.

[0036] [Figure 6] FIG. 1 illustrates an example system for managing cell sites in a wireless access network, in accordance with some implementations of the subject matter of this disclosure.

[0037] [Figure 7] FIG. 1 illustrates an example process for setting up a cell site node, according to some implementations of the disclosed subject matter.

[0038] [Figure 8] FIG. 1 illustrates an example process for cell site node management, in accordance with some implementations of the disclosed subject matter.

[0039] [Figure 9] 9 illustrates an example process for performing cell site node verification in the process for cell site node management of FIG. 8 in accordance with some implementations of the subject matter of this disclosure.

[0040] [Figure 10] 9 illustrates an example process for a cell site node to obtain an operator certificate in the process for cell site node management of FIG. 8 in accordance with some implementations of the subject matter of this disclosure.

[0041] [Figure 11] 9 illustrates an example process for registering a cell site node with a cellular network in the process for cell site node management of FIG. 8 in accordance with some implementations of the subject matter of this disclosure.

[0042] [Figure 12a] 9 illustrates a portion of an example process for managing cell site node infrastructure in the process for cell site node management of FIG. 8 in accordance with some implementations of the subject matter of this disclosure.

[0043] [Figure 12b] FIG. 12b illustrates another portion of the process for managing the cell site node infrastructure of FIG. 12a.

[0044] [Figure 13] 13 illustrates an example process 1300 for provisioning cell site infrastructure in the process for cell site node management of FIG. 8 in accordance with some implementations of the subject matter of this disclosure.

[0045] [Figure 14] FIG. 1 illustrates an example system in accordance with some implementations of the disclosed subject matter.

[0046] [Figure 15] 1 illustrates an example method according to some implementations of the disclosed subject matter. DETAILED DESCRIPTION OF THE INVENTION

[0047] The subject matter of the present disclosure may provide systems and methods that may be implemented in wireless communication systems, including various wireless communication systems, including 5G New Radio (NR) communication systems, Long Term Evolution communication systems, and the like.

[0048] Generally, the subject matter of this disclosure relates to managing cell sites in a radio access network (RAN).

[0049] In some implementations of the subject matter of this disclosure, devices at cell sites in a radio access network (RAN), such as an open RAN (O-RAN), can be configured to operate a cloud infrastructure thereon. Operating a cloud infrastructure on a device, also referred to herein as a “node” or “cell site node,” may enable time-sensitive and / or real-time RAN applications to be run at the cell site, e.g., the cell site node, instead of at a location remote from the cell site, such as a cell site operator's central management system. Operating a cloud infrastructure on a device may reduce network bandwidth usage because the RAN applications can be installed on the device itself, eliminating the need for the device to communicate with a server or other hardware remote from the cell site, such as a cell site operator's central management system, to access the RAN applications. Because network bandwidth is typically highly constrained between the cell site and the server, reducing network bandwidth associated with RAN applications frees up bandwidth for other uses, thereby potentially speeding up and / or otherwise improving overall network functionality. Running the cloud infrastructure on the device may improve security over running the cloud infrastructure on a server or other hardware located remotely from the cell site because the cloud infrastructure is installed on the device itself and the device does not need to communicate securely with a server or other hardware to access the RAN application. While secure communications are typically effective and secure, they can be compromised by hacker or other malicious activity and / or may become temporarily unavailable due to, for example, network connectivity issues.

[0050] One or more aspects of the subject matter of this disclosure may be incorporated into transmitter and / or receiver components of base stations (e.g., gNodeBs, eNodeBs, etc.) in such communication systems. The following is a general discussion of Long Term Evolution and 5G New Radio (NR) communication systems.

[0051] I. Long Term Evolution Communication System 1a-1c and 2 illustrate an exemplary conventional Long Term Evolution (LTE) communication system 100 along with its various components. The LTE system, or 4G LTE, as it is commercially known, is defined by a standard for high-speed data wireless communication for mobile phones and data terminals. The standard is an evolution of GSM / EDGE (Global System for Mobile Communications / Enhanced Data rates for GSM Evolution) and UMTS / HSPA (Universal Mobile Telecommunications System / High Speed ​​Packet Access) network technologies. The standard was developed by 3GPP (3rd Generation Partnership Project).

[0052] As shown in FIG. 1a, the system 100 may include an Evolved Universal Terrestrial Radio Access Network (EUTRAN) 102, an Evolved Packet Core (EPC) 108, and a Packet Data Network (PDN) 101, where the EUTRAN 102 and the EPC 108 provide communications between user equipment 104 and the PDN 101. The EUTRAN 102 may include multiple Evolved Node Bs (eNodeBs or ENODEBs or enodeb or eNBs) or base stations 106(a, b, c) (as shown in FIG. 1b) that provide communications capabilities to multiple user equipment 104(a, b, c). The user equipment 104 may be a mobile phone, a smartphone, a tablet, a personal computer, a personal digital assistant (PDA), a server, a data terminal, and / or any other type of user equipment, and / or any combination thereof. User equipment 104 can connect to the EPC 108 and ultimately to the PDN 101 via any eNodeB 106. Typically, user equipment 104 can connect to the eNodeB 106 that is closest in terms of distance. In the LTE system 100, the EUTRAN 102 and the EPC 108 cooperate to provide connectivity, mobility, and services to user equipment 104.

[0053] Figure 1b illustrates further details of the network 100 shown in Figure 1a. As mentioned above, the EUTRAN 102 includes multiple eNodeBs 106, also known as cell sites. The eNodeBs 106 provide radio functionality and perform key control functions, including air link resource scheduling or radio resource management, active mode mobility or handover, and admission control for services. The eNodeBs 106 are responsible for selecting which mobility management entity (Mobility Management Entities (MMEs) as shown in Figure 1c) will serve the user equipment 104, as well as protocol features such as header compression and encryption. The eNodeBs 106 that comprise the EUTRAN 102 cooperate with each other for radio resource management and handover.

[0054] Communication between the user equipment 104 and the eNodeB 106 occurs over an air interface 122 (also known as the LTE-Uu interface). As shown in FIG. 1b, the air interface 122 provides communication between the user equipment 104b and the eNodeB 106a. The air interface 122 uses Orthogonal Frequency Division Multiple Access (OFDMA) and Single Carrier Frequency Division Multiple Access (SC-FDMA), an OFDMA variant, on the downlink and uplink, respectively. OFDMA allows the use of multiple known antenna techniques, such as Multiple Input Multiple Output (MIMO).

[0055] The air interface 122 uses various protocols, including Radio Resource Control (RRC) for signaling between the user equipment 104 and the eNodeB 106 (as shown in FIG. 1c) and Non-Access Stratum (NAS) for signaling between the user equipment 104 and the MME. In addition to signaling, user traffic is transferred between the user equipment 104 and the eNodeB 106. Both signaling and traffic in the system 100 are carried by Physical Layer (PHY) channels.

[0056] Multiple eNodeBs 106 may be interconnected with each other using X2 interfaces 130(a, b, c). As shown in FIG. 1b, X2 interface 130a provides interconnection between eNodeB 106a and eNodeB 106b, X2 interface 130b provides interconnection between eNodeB 106a and eNodeB 106c, and X2 interface 130c provides interconnection between eNodeB 106b and eNodeB 106c. The X2 interfaces may be established between two eNodeBs to provide for the exchange of signals, which may include information related to loading or interference, as well as information related to handover. The eNodeBs 106 communicate with the evolved packet core 108 via S1 interfaces 124(a, b, c). The S1 interface 124 can be split into two interfaces, one for the control plane (shown in FIG. 1c as control plane interface (S1-MME interface) 128) and the other for the user plane (shown in FIG. 1c as user plane interface (S1-U interface) 125).

[0057] The EPC 108 establishes and enforces Quality of Service (QoS) for user services and enables user equipment 104 to maintain a consistent Internet Protocol (IP) address while moving. Note that each node in the network 100 has its own IP address. The EPC 108 is designed to interwork with legacy wireless networks. The EPC 108 is also designed to separate the control plane (i.e., signaling) and the user plane (i.e., traffic) in the core network architecture, which allows for more flexibility in implementation and independent scalability of control and user data functions.

[0058] The EPC 108 architecture is dedicated to packet data and is shown in more detail in Figure 1c. The EPC 108 includes a serving gateway (S-GW) 110, a PDN gateway (P-GW) 112, a mobility management entity (MME) 114, a home subscriber server (HSS) 116 (a subscriber database for the EPC 108), and a policy control and charging rules function (PCRF) 118. Some of these (such as the S-GW, P-GW, MME, and HSS) are often combined into a node, depending on the manufacturer's implementation.

[0059] The S-GW 110 functions as an IP packet data router and is the bearer path anchor for the user equipment within the EPC 108. Thus, when the user equipment moves from one eNodeB 106 to another during mobility operation, the S-GW 110 remains the same and the bearer path towards the EUTRAN 102 is switched to communicate with the new eNodeB 106 serving the user equipment 104. If the user equipment 104 moves to the domain of a different S-GW 110, the MME 114 will forward all of the user equipment's bearer path to the new S-GW. The S-GW 110 establishes a bearer path for the user equipment to one or more P-GWs 112. When downstream data is received for an idle user equipment, the S-GW 110 buffers the downstream packets and requests the MME 114 to identify and re-establish a bearer path to and through the EUTRAN 102.

[0060] The P-GW 112 is the gateway between the EPC 108 (and user equipment 104 and EUTRAN 102) and the PDN 101 (shown in FIG. 1a). The P-GW 112 acts as a router for user traffic and performs functions on behalf of the user equipment. These include allocating IP addresses to the user equipment, packet filtering of downstream user traffic to ensure it is placed on the appropriate bearer path, and enforcing downstream QoS, including data rate. Depending on the services a subscriber is using, there may be multiple user data bearer paths between the user equipment 104 and the P-GW 112. A subscriber may use services on PDNs served by different P-GWs, in which case the user equipment has at least one bearer path established to each P-GW 112. If the S-GW 110 is also changing during a handover of the user equipment from one eNodeB to another, the bearer path from the P-GW 112 is switched to the new S-GW.

[0061] The MME 114 manages user equipment 104 within the EPC 108, including managing subscriber authentication, maintaining context for authenticated user equipment 104, establishing data bearer paths within the network for user traffic, and tracking the location of idle mobiles that have not detached from the network. For idle user equipment 104 that needs to reconnect to the access network to receive downstream data, the MME 114 initiates paging to locate the user equipment and reestablishes the bearer path to and through the EUTRAN 102. The MME 114 for a particular user equipment 104 is selected by the eNodeB 106 from which the user equipment 104 initiates system access. An MME is typically part of a collection of MMEs within the EPC 108 for load sharing and redundancy purposes. In establishing a user's data bearer path, the MME 114 is responsible for selecting the P-GW 112 and the S-GW 110, which constitute the termination points of the data path through the EPC 108.

[0062] The PCRF 118 is responsible for controlling policy control decision making and flow-based charging functionality within the Policy Control Enforcement Function (PCEF) residing in the P-GW 110. The PCRF 118 provides QoS authorization (QoS Class Identifier (QCI) and bit rate), which determines how a particular data flow is treated within the PCEF and ensures that this is in accordance with the user's subscription profile.

[0063] As mentioned above, IP services 119 are provided by PDN 101 (as shown in FIG. 1a).

[0064] 1d is a diagram illustrating an example structure of an eNodeB 106. The eNodeB 106 can include at least one Remote Radio Head (RRH) 132 (typically, there may be three RRHs 132) and a Baseband Unit (BBU) 134. The RRHs 132 can be connected to an antenna 136. The RRHs 132 and BBU 134 can be connected using an optical interface that conforms to the Common Public Radio Interface (CPRI) / extended CPRI (eCPRI) 142 standard specification, either using RRH-specific custom control and user plane framing methods or using O-RAN Alliance compliant control and user plane framing methods. The operation of the eNodeB 106 can be characterized using the following standard parameters (and specifications): radio frequency band (Band 4, Band 9, Band 17, etc.), bandwidth (5, 10, 15, 20 MHz), access method (downlink: OFDMA, uplink: SC-OFDMA), antenna technology (single-user and multi-user MIMO, uplink: single-user and multi-user MIMO), number of sectors (up to 6), maximum transmission speed (downlink: 150 Mb / s, uplink: 50 Mb / s), S1 / X2 interface (1000Base-SX, 1000Base-T), and mobile environment (up to 350 km / h). The BBU 134 can be responsible for digital baseband signal processing, S1 line termination, X2 line termination, call processing, and monitoring control processing. IP packets received from the EPC 108 (not shown in FIG. 1d) can be modulated into digital baseband signals and transmitted to the RRH 132. Conversely, digital baseband signals received from the RRH 132 can be demodulated into IP packets for transmission to the EPC 108.

[0065] The RRH 132 can transmit (send) and receive wireless signals using the antenna 136. The RRH 132 can convert digital baseband signals from the BBU 134 (using a converter (CONV) 140) to radio frequency (RF) signals and power amplify them (using an amplifier (AMP) 138) for transmission to the user equipment 104 (not shown in FIG. 1d). Conversely, radio frequency (RF) signals received from the user equipment 104 are amplified (using the AMP 138) and converted (using the CONV 140) to digital baseband signals for transmission to the BBU 134.

[0066] Figure 2 illustrates additional details of an exemplary eNodeB 106. The eNodeB 106 includes multiple layers: LTE Layer 1 (202), LTE Layer 2 (204), and LTE Layer 3 (206). LTE Layer 1 includes the physical layer (PHY). LTE Layer 2 includes medium access control (MAC), radio link control (RLC), and packet data convergence protocol (PDCP). LTE Layer 3 includes various functions and protocols, including radio resource control (RRC), dynamic resource allocation, eNodeB measurement configuration and provisioning, radio admission control, connection mobility control, and radio resource management (RRM). The RLC protocol is an automatic repeat request (ARQ) fragmentation protocol used over the cellular air interface. The RRC protocol handles LTE Layer 3 control plane signaling between user equipment and the EUTRAN. The RRC includes functions for connection establishment and release, system information broadcast, radio bearer establishment / reconfiguration and release, RRC connection mobility procedures, paging notification and release, and outer loop power control. The PDCP performs IP header compression and decompression, user data transfer, and radio bearer sequence number maintenance. The BBU 134 shown in FIG. 1d may include LTE layers L1 to L3.

[0067] One of the primary functions of the eNodeB 106 is radio resource management, which includes scheduling both uplink and downlink air interface resources for the user equipment 104, control of bearer resources, and admission control. As an agent for the EPC 108, the eNodeB 106 is responsible for forwarding paging messages used to locate a mobile when it is idle. The eNodeB 106 also communicates common control channel information over the air, communicates header compression, encryption and decryption of user data transmitted over the air, and establishes handover reporting and trigger criteria. As mentioned above, the eNodeB 106 can cooperate with other eNodeBs 106 via the X2 interface for handover and interference management purposes. The eNodeB 106 communicates with the MME of the EPC via the S1-MME interface and to the S-GW using the S1-U interface. Additionally, the eNodeB 106 exchanges user data with the S-GW via the S1-U interface. The eNodeB 106 and the EPC 108 have a many-to-many relationship to support load sharing and redundancy between the MMEs and the S-GWs. The eNodeB 106 selects an MME from a group of MMEs so that the load can be shared by multiple MMEs to avoid congestion.

[0068] II. 5G NR Wireless Communication Network In some implementations, the subject matter of this disclosure relates to 5G new radio (NR) communication systems. 5G NR is the next communication standard beyond the 4G / IMT-Advanced standard. 5G networks offer higher capacity than current 4G, allowing for a larger number of mobile broadband users per area, and allowing for consumption of more and / or unlimited data volumes in gigabytes per month and per user. This can enable users to stream high-definition media for many hours per day using their mobile devices, even when Wi-Fi networks do not allow for this. 5G networks have improved support for device-to-device communication, lower costs, lower latency than 4G equipment, and lower battery consumption. Such networks have data rates of tens of megabits per second for many users, data rates of 100 Mb / s for metropolitan areas, simultaneous 1 Gb / s to users within a small confined area (e.g., an office floor), many simultaneous connections for wireless sensor networks, enhanced spectral efficiency, improved coverage, enhanced signaling efficiency, 1-10 ms latency, and reduced latency compared to existing systems.

[0069] 3 is a diagram illustrating an example virtual radio access network 300. The network 300 can provide communication for various components, including base stations (e.g., eNodeBs, gNodeBs) 301, radio equipment 307, a centralized unit 302, a digital unit 304, and wireless devices 306. The components in the system 300 can be communicatively coupled to a core using backhaul links 305. The centralized unit (CU) 302 can be communicatively coupled to a distributed unit (DU) 304 using a midhaul connection 308. The radio frequency (RU) component 306 can be communicatively coupled to the DU 304 using a fronthaul connection 310.

[0070] In some implementations, the CU 302 can provide intelligent communication capabilities to one or more DU units 308. The units 302, 304 can include one or more base stations, macro base stations, micro base stations, remote radio heads, etc., and / or any combination thereof.

[0071] In a lower layer split architecture environment, the CPRI bandwidth requirement for the NR can be several hundred Gb / s. CPRI compression can be implemented in the DU and RU (as shown in Figure 3). In 5G communication systems, compressed CPRI over Ethernet frames is referred to as eCPRI, which is the recommended fronthaul network. This architecture can enable standardization of fronthaul / midhaul, which can include upper layer splitting (e.g., Option 2 or Option 3-1 (upper / lower RLC split architecture)) and fronthaul using an L1 split architecture (Option 7).

[0072] In some implementations, a lower layer split architecture (e.g., Option 7) can include a receiver in the uplink and joint processing across multiple Transmission Points (TPs) for both DL / UL and transport bandwidth and latency requirements to facilitate deployment. Additionally, the lower layer split architecture of the presently disclosed subject matter can include splitting between cell-level processing and user-level processing, which can include cell-level processing in a Remote Unit (RU) and user-level processing in a DU. Additionally, using the lower layer split architecture of the presently disclosed subject matter, frequency-domain samples can be transported over the Ethernet fronthaul, and the frequency-domain samples can be compressed for reduced fronthaul bandwidth.

[0073] 4 is a diagram illustrating an example communication system 400 that can implement 5G technology and provide its users with use of higher frequency bands (e.g., greater than 10 GHz). The system 400 can include a macro cell 402 and small cells 404, 406.

[0074] The mobile device 408 can be configured to communicate with one or more of the small cells 404, 406. The system 400 can enable splitting of the control plane (C-plane) and user plane (U-plane) between the macrocell 402 and the small cells 404, 406, where the C-plane and U-plane utilize different frequency bands. In particular, the small cells 404, 406 can be configured to utilize higher frequency bands when communicating with the mobile device 408. The macrocell 402 can utilize existing cellular bands for C-plane communications. The mobile device 408 can be communicatively coupled via the U-plane 412, where the small cell (e.g., the small cell 406) can provide higher data rates and more flexible, cost-effective, and energy-efficient operation. The macrocell 402 can maintain good connectivity and mobility via the C-plane 410. Furthermore, in some cases, LTE and NR can transmit on the same frequency.

[0075] 5a is a diagram illustrating an example 5G wireless communication system 500 according to some implementations of the subject matter of this disclosure. The system 500 may be configured to have a lower layer split architecture according to Option 7-2. The system 500 may include a core network 502 (e.g., 5G Core) and one or more gNodeBs (or gNBs), where the gNBs may have a centralized unit gNB-CU. The gNB-CU may be logically divided into a control plane portion gNB-CU-CP 504 and one or more user plane portions gNB-CU-UP 506. The control plane portion 504 and the user plane portion 506 may be configured to be communicatively coupled using an E1 communication interface 514 (as defined in the 3GPP standard). The control plane portion 504 may be configured to be responsible for executing the RRC and PDCP protocols of the radio stack.

[0076] The control plane portion 504 and user plane portion 506 of the centralized unit of the gNB can be configured to be communicatively coupled to one or more distributed units (DUs) 508, 510 according to an upper layer split architecture. The distributed units 508, 510 can be configured to execute upper portions of the RLC, MAC, and PHY layer protocols of the radio stack. The control plane portion 504 can be configured to be communicatively coupled to the distributed units 508, 510 using an F1-C communication interface 516, and the user plane portion 506 can be configured to be communicatively coupled to the distributed units 508, 510 using an F1-U communication interface 518. The distributed units 508, 510 can be coupled to one or more remote radio units (RUs) 512 via a fronthaul network 520 (which may include one or more switches, links, etc.), which then communicate with one or more user equipment (not shown in FIG. 5a). The remote radio unit 512 may be configured to execute lower portions of the PHY layer protocol and provide antenna capabilities to the remote unit for communication with user equipment (similar to that discussed above in connection with Figures 1a-2).

[0077] FIG. 5b illustrates an example layer architecture 530 for a split gNB. The architecture 530 can be implemented within the communication system 500 shown in FIG. 5a, which can be configured as a virtualized disaggregated radio access network (RAN) architecture. This allows layers L1, L2, L3, and radio processing to be virtualized and disaggregated within centralized, distributed, and radio units. As shown in FIG. 5b, the gNB-DU 508 can be communicatively coupled to the gNB-CU-CP control plane portion 504 and the gNB-CU-UP user plane portion 506 (also shown in FIG. 5a). Each of the components 504, 506, 508 can be configured to include one or more layers.

[0078] The gNB-DU 508 may include RLC, MAC, and PHY layers, as well as various communications sublayers. These may include an F1-Application Protocol (F1-AP) sublayer, a GPRS Tunneling Protocol (GTPU) sublayer, a Stream Control Transmission Protocol (SCTP) sublayer, a User Datagram Protocol (UDP) sublayer, and an Internet Protocol (IP) sublayer. As described above, the distributed unit 508 may be communicatively coupled to the control plane portion 504 of the centralized unit, which may also include the F1-AP, SCTP, and IP sublayers, as well as a Radio Resource Control and PDCP Control (PDCP-Control) sublayer. Furthermore, the distributed unit 508 may also be communicatively coupled to the user plane portion 506 of the centralized unit of the gNB. The user plane portion 506 may include the Service Data Adaptation Protocol (SDAP), PDCP-User (PDCP-U), GTPU, UDP, and IP sublayers.

[0079] Figure 5c illustrates an example functional division in the gNB architecture shown in Figures 5a-5b. As shown in Figure 5c, the gNB-DU 508 may be communicatively coupled to the gNB-CU-CP 504 and the GNB-CU-UP 506 using an F1-C communication interface. The gNB-CU-CP 504 and the GNB-CU-UP 506 may be communicatively coupled using an E1 communication interface. The upper portion of the PHY layer (or Layer 1) may be performed by the gNB-DU 508, while the lower portion of the PHY layer may be performed by the RU (not shown in Figure 5c). As shown in Figure 5c, the RRC portion and the PDCP-C portion may be performed by the control plane portion 504, and the SDAP portion and the PDCP-U portion may be performed by the user plane portion 506.

[0080] Some of the functions of the PHY layer in a 5G communication network include error detection on transport channels and indication to higher layers, Fast EtherChannel (FEC) encoding / decoding of transport channels, hybrid ARQ soft combining, rate matching of coded transport channels to physical channels, mapping of coded transport channels to physical channels, power weighting of physical channels, modulation and demodulation of physical channels, frequency and time synchronization, radio characteristic measurements and indication to higher layers, MIMO antenna processing, digital and analog beamforming, RF processing, and other functions.

[0081] The MAC sublayer of Layer 2 performs beam management, random access procedures, mapping between logical channels and transport channels, concatenation of multiple MAC service data units (SDUs) belonging to one logical channel into a transport block (TB), multiplexing / demultiplexing of SDUs belonging to logical channels to / from the TB passed to / from the physical layer on the transport channel, scheduling information reporting, error correction through hybrid automatic repeat request (HARQ), priority handling between logical channels for one UE, priority handling between UEs through dynamic scheduling, transport format selection, and other functions. The RLC sublayer's functions include forwarding upper layer packet data units (PDUs), error correction through ARQ, reordering of data PDUs, duplication and protocol error detection, reestablishment, etc. The PDCP sublayer is responsible for forwarding user data, various functions during the reestablishment procedure, retransmission of SDUs, discarding SDUs in the uplink, forwarding of control plane data, etc.

[0082] The RRC sublayer of Layer 3 may perform the broadcasting of system information to the NAS and Access Stratum (AS), establishment, maintenance, and release of RRC connections, security, establishment, configuration, maintenance, and release of point-to-point radio bearers, mobility functions, reporting, and other functions.

[0083] III. Cell Site Management in Radio Access Networks In some implementations of the subject matter of this disclosure, devices at cell sites in a radio access network (RAN), such as an open RAN (O-RAN), can be configured to operate a cloud infrastructure thereon. Operating a cloud infrastructure on a device, also referred to herein as a “node” or “cell site node,” may enable time-sensitive and / or real-time RAN applications to be operated at the cell site, e.g., the cell site node, instead of at a location remote from the cell site, such as a cell site operator's central management system. Operating a cloud infrastructure on a device may reduce network bandwidth usage because RAN applications can be installed on the device itself, eliminating the need for the device to communicate with a server or other hardware remote from the cell site, such as a cell site operator's central management system, to access the RAN applications. Because network bandwidth is typically highly constrained between the cell site and the server, reducing network bandwidth associated with RAN applications frees up bandwidth for other uses, thereby speeding up and / or otherwise improving overall network functionality. Running the cloud infrastructure on the device can improve security over running the cloud infrastructure on a server or other hardware located remotely from the cell site because the cloud infrastructure is installed on the device itself and the device does not need to communicate securely with a server or other hardware to access the RAN application. While secure communications are typically effective and secure, they can be compromised by hacker or other malicious activity and / or can become temporarily unavailable due to, for example, network connectivity issues.

[0084] The device can be configured to manage a cloud infrastructure thereon. The device can be configured to automatically configure a cloud infrastructure thereon. Thus, the device does not need to be configured via a secure connection to a server or other hardware, which may be compromised by hacker activity or other malicious activity and / or may become temporarily unavailable, as described above. The device at the cell site also does not require manual intervention to initiate configuration of the cloud infrastructure thereon. Thus, personnel (users, engineers) do not need to travel to the cell site to manually configure the cloud infrastructure thereon, which would be time-consuming and costly. Because multiple devices are typically deployed at each of multiple cell sites, the time and cost savings of providing automatic configuration of the cloud infrastructure at the device can be significant. Furthermore, because cell sites are typically physically insecure, the cell site node is typically in an insecure location, making the cell site node vulnerable to physical attacks and tampering. Thus, not requiring personnel to be physically present at the cell site in connection with the cloud infrastructure may reduce the number of visits by personnel to the cell site, which may reduce the opportunities for physical attacks and tampering, and / or may make it easier to identify possible physical attacks and tampering, as persons present at the cell site may be more easily identifiable as potential threats to the security of the cell site.

[0085] The device may have an agent, also referred to herein as a "software agent," installed on the device, e.g., stored in the device's memory, before the device is delivered to the cell site. For example, the agent may be installed on the device, e.g., stored in the device's memory, as part of the device's manufacturing process. After the device is delivered to the cell site and set up as needed, e.g., by being removed from its packaging, connected to power, etc., the agent may be configured to automatically trigger an installation process in which cloud infrastructure is configured on the device. The installation process may include the device communicating with the software, which may include one or more RAN applications, to download the software from a server or other hardware located remotely from the cell site, such as a cell site operator's central management system located remotely from the cell site. The software may include multiple software modules. Each of the software modules may correspond to a RAN application. The installation process may also include the downloaded software being installed on the device, e.g., resident in the device's memory and executable by the device's processor, so that the downloaded software is ready for use.

[0086] An agent installed on the device may enable the cloud infrastructure to be installed on the device as appropriate for the particular cell site where the device is deployed. Different cell sites may have different requirements, for example, based on location, other devices at the cell site with which the cell site node must communicate, etc. Thus, the cell site node may not have unnecessary software installed thereon, thereby conserving computer system resources for other uses and / or ensuring that the cell site node is compatible with other devices at the cell site.

[0087] An agent installed on a cell site node may enable the cloud infrastructure installed thereon to be updated at any time and any number of times. Thus, the cloud infrastructure may be able to operate most efficiently with the latest available software, e.g., the latest available RAN application. A server or other hardware located remotely from the cell site, such as a cell site operator's central management system located remotely from the cell site, may be configured to trigger updates by transmitting messages to the device. Thus, the device may be dynamically updated as needed, thereby enabling it to use the latest software, e.g., the latest RAN application, without the need for personnel to visit the cell site to manually provide the update.

[0088] In some implementations, the device includes a base station (e.g., a gNodeB or gNB, an eNodeB or eNB, an ng-eNodeB or ng-eNB), such as those shown in and discussed above with respect to Figures 1a-5c. In some implementations, the device includes a DU (e.g., the DU 304 of Figure 3, the DUs 508, 510 of Figures 5a-5c, etc.) of the base station.

[0089] 6 is a diagram illustrating an example system 600 for managing cell sites in a radio access network in accordance with some implementations of the subject matter of this disclosure. System 600 may include a radio access network such as an O-RAN operating in a wireless communication system (e.g., 4G, LTE, 5G, etc.). As in this illustrated implementation, system 600 includes one or more distributed units DU1 (labeled 602a), DU2 (labeled 602b), ...DU n (602n), a Service Management and Orchestration (SMO) component 604, and a Radio Unit (RU) 606.

[0090] The DUs 602a, 602b, ... 602n can be configured to be communicatively coupled to an SMO component 604. The SMO component 604 can be configured to be communicatively coupled to an RU 606. Two or more DUs 602a, 602b, ... 602n can be configured to be communicatively coupled to one another, where one of the DUs 602a, 602b, ... 602n (e.g., the first DU 602a) can be implemented and / or serve as a host and / or primary distributed unit, while one or more of the other DUs 602a, 602b, ... 602n (e.g., the second through nth DUs 602b, ... 602n) can be implemented and / or serve as tenant and / or secondary and / or shared resource operator distributed units.

[0091] 7 is a diagram illustrating an example process 700 for cell site node setup in accordance with some implementations of the subject matter of this disclosure. Generally, the cell site node setup process 700 can set up a cell site node for cloud infrastructure management. The cell site node setup process 700 can be performed entirely before the cell site node begins communicating over a cellular network.

[0092] The cell site node being set up in cell site node setup process 700 may be a DU (e.g., a distributed unit such as DU 304 of FIG. 3, DUs 508 and 510 of FIGS. 5a-5c, or DUs 602a, 602b, and 602n of FIG. 6). Process 700 may be performed using a system described herein, such as system 600 shown in FIG. 6. In particular, one of the DUs 602a, 602b, ..., and 602n may be the cell site node being set up, and process 700 may be performed for any number of DUs 602a, 602b, ..., and 602n (e.g., all of the DUs 602a, 602b, ..., and 602n) to set up each of the any number of DUs 602a, 602b, ..., and 602n.

[0093] The cell site node setup process 700 may include installing (702) an agent at the cell site node. Installing (702) the agent may generally include storing the agent in a memory at the cell site node. The agent may be configured to be executed by a processor, for example, a processor at the cell site node communicatively coupled to the memory that stores the agent. The agent may be configured to be automatically executed by the processor, as discussed further below. Execution of the agent may be configured to initiate verification of the cell site node and, after verification, to initiate configuration of a cloud infrastructure on the cell site node, as also discussed further below.

[0094] The installing (702) may also include installing a vendor certificate, also referred to herein as a "first certificate," on the cell site node. The vendor certificate may be provided by a vendor (e.g., a manufacturer, a verified seller, etc.) of the cell site node. The vendor certificate may certify that the cell site node is a verified cell site node of the vendor. The installing (702) of the vendor certificate generally may include storing the vendor certificate in a memory of the cell site node.

[0095] The agent and vendor certificate may be installed (702) on the cell site node during manufacturing of the cell site node. Installing the agent and vendor certificate (702) during manufacturing may help ensure that the agent and vendor certificate are not corrupted and / or available for immediate use when the cell site node is first used, such as when the cell site node is first powered on at the cell site. Installing the agent and vendor certificate (702) may occur at any appropriate point during the manufacturing process that allows the agent and vendor certificate to be successfully and securely installed on the cell site node. The agent may be installed (702) before the vendor certificate, or the vendor certificate may be installed (702) before the agent.

[0096] The cell site node setup process 700 may also include, after the agent and certificate are installed on the cell site node (702), handing over the cell site node to a cell site where the cell site node will be deployed and used for communications in a wireless communication system (704). After manufacture, the cell site node may be turned over to the cell site (704) by any number of authorized personnel, in any number of ways, and along any number of transport paths, according to a typical handover process for the particular cell site node.

[0097] After the cell site node is delivered (704) to the cell site and set up (706) as needed, the cell site node can be powered on (708), such as by removing it from packaging and connecting it to power. In some implementations, powering on (708) the cell site node can automatically trigger the execution of an agent (702) installed on the cell site node, e.g., trigger a processor to execute an agent stored in memory. Thus, the cloud infrastructure can be automatically configured at the cell site node in response to powering on (708) the device. Thus, time delays in cloud infrastructure configuration can be avoided. Automatic configuration of the cloud infrastructure can be achieved without personnel having to access the device, e.g., to provide input thereto, since simply powering on (708) the device can trigger the installation of the cloud infrastructure. do Security may be improved because configuration of the cloud infrastructure does not need to be initiated. In other implementations, execution of the agent may be manually triggered after the cell site node is powered on (708). Manually triggering execution of the agent may allow for delaying use of devices at the cell site, which may be desirable, for example, if testing is desired before full use of the device. Manual triggering may be performed locally by cell site field personnel authorized to access the device.

[0098] For example, after the cell site node is set up according to the cell site node setup process 700 of Figure 7, the cloud infrastructure can be managed at the cell site node. Figure 8 illustrates an example process 800 for cell site node management according to some implementations of the subject matter of this disclosure. Generally, the cell site node management process 800 can manage the cloud infrastructure at the cell site node.

[0099] The cell site node management process 800 may include performing 802 verification of the cell site node. Generally, verification of the cell site node may involve a first server, for example, a server of a cellular network operator, such as a Dynamic Host Configuration Protocol (DHCP) server (e.g., as provided by a PDN, such as PDN 101 of FIG. 1), authorizing the cell site node based on a vendor certificate installed on the cell site node. The cell site node may encrypt the vendor certificate and send the encrypted vendor certificate to the first server, which may decrypt and verify the vendor certificate.

[0100] If the cell site node is authorized by verifying the vendor certificate, the cell site node is authorized to communicate on the cellular network with which the cell site is associated, the first server can transmit to the cell site node an IP address for the cell site node to use to communicate on the wireless network, and the cell site node management process 800 continues.

[0101] If the cell site node is unauthorized by not verifying the vendor certificate, the cell site node is not authorized to communicate on the cellular network with which the cell site is associated, and the cell site node management process 800 terminates. Thus, unauthorized devices may be prevented from communicating on the cellular network. If the cell site node is unauthorized by not verifying the vendor certificate, an error handling process may be implemented. The error handling process may address the presence of an unauthorized device in accordance with the cell site operator's conventional error handling protocol, such as by retrying the validation a predetermined number of times (e.g., once, twice, etc.) within a predetermined time period (e.g., 30 seconds, one minute, etc.) before finalizing a determination of unauthorized status. A determination of unauthorized status may automatically trigger an alarm, such as an email transmission, an audible tone, or a visible warning light, notifying appropriate personnel that manual intervention may be required to address the issue.

[0102] 9 is a diagram illustrating an example process 900 for performing 802 verification of a cell site node according to some implementations of the subject matter of this disclosure. Figure 9 illustrates communication between the cell site node and a first server, shown in Figure 9 as a DHCP server. As will be appreciated by those skilled in the art, communication between the cell site node and the first server can be secured, such as by using encryption.

[0103] The cell site node validation process 900 can include an agent installed on the cell site node that identifies 902 the management virtual local area network (MGMT VLAN), enterprise number, and interface from provisioning data pre-installed on the cell site node during manufacturing. The process 900 can also include an agent that creates 904 any bonded single root I / O virtualization (SRIOV) interfaces needed to set up the MGMT VLAN interface.

[0104] The cell site node verification process 900 may also include, after identifying 902 and creating 904, the cell site node transmitting 906 a request (e.g., a DHCPv6 solicitation request) to a DHCP server via the identified 902 MGMT VLAN. The request may include the identified enterprise number and may include an identification of the cell site node. The identification may be, for example, a device serial number. In this illustrated embodiment, the cell site node is a DU, and therefore, the identification of the cell site node shown in FIG. 9 is a DU identification (DUID).

[0105] The DHCP server receives the request and performs security authorization (908) to authorize the cell site node. The DHCP server can use the identification information, e.g., the DUID, as a key to identify an Infrastructure Management Services (IMS) Uniform Resource Identifier (URI) for the cell site node. The IMS URI identification is cell If the key cannot identify an IMS URI, the Site Node certifies that it is authentic. cell The site node cannot be certified as authentic.

[0106] After performing security authorization and authorization for the cell site node (908), the DHCP server can transmit an Advertising (ADV) message to the cell site node (910). The ADV message can include an enterprise number, a nonce, an IP address (e.g., an IPv6 address) for use by the cell site node, and a lifetime.

[0107] The cell site node receives the ADV message and, in response, transmits a second request to the DHCP server 912. The second request may include a vendor certificate installed on the cell site node, a signed nonce, a signed cloud (e.g., gcloud (Google Cloud) or other cloud) identification (which may be the cell site node product serial number), the cell site node identification, and an IP address.

[0108] The DHCP server receives the second request and, in response, transmits a response to the DHCP server (914). This response may include information that the cell site node may subsequently use to enable the cell site node to communicate over the cellular network. As shown in Figure 9, the information may include a Certificate Authority (CA) root certificate, a CA server Fully Qualified Domain Name (FQDN), and an IMS URI.

[0109] In some cases, the cell site node may not have a vendor certificate, also referred to herein as an “operator certificate,” pre-installed thereon and may therefore first obtain the vendor certificate from the vendor server before transmitting 912 to the DHCP server in the second request. FIG. 10 illustrates an example process 1000 for a cell site node to obtain an operator certificate in accordance with some implementations of the subject matter of this disclosure. FIG. 10 illustrates communication between the cell site node and the vendor server. As will be appreciated by those skilled in the art, communication between the cell site node and the vendor server may be secured, such as by using encryption. As shown in FIG. 10, a first certificate (shown in FIG. 10 as a vendor DU device certificate and private key) may be pre-installed on the cell site node, e.g., installed 702 in process 700 of FIG. 7. As also shown in Figure 10, the FQDN and IMS URL (shown in Figure 10 as Vendor CA Info), and the CA root certificate (shown in Figure 10 as CA Certificate (cacert)) may be obtained from a DHCP server, for example, in process 900 of Figure 9. As further shown in Figure 10, the vendor certificate may be pre-installed on the vendor server. The vendor certificate may be pre-installed on the vendor server during manufacturing, or at another time before initiating the operator certificate acquisition process 1000, or otherwise installed thereon before initiating the cell site node management process 800.

[0110] The operator certificate acquisition process 1000 is DoThe vendor certificate request may include the cell site node transmitting the vendor certificate request to the vendor server (1002). The FQDN and IMS URL that the cell site node receives from the DHCP server may enable the cell site node to know where to direct the vendor certificate request to the vendor server. As shown in Figure 10, the vendor certificate request may be in the form of an HTTP request. The vendor server receives the vendor certificate request and, in response, transmits the vendor certificate to the cell site node (1004).

[0111] If the cell site node does not receive the vendor certificate from the vendor server during the operator certificate acquisition process 1000, an error handling process may be implemented. The error handling process may address the non-receipt of the vendor certificate in accordance with the cell site operator's conventional error handling protocol, such as by having the cell site node reattempt to contact the vendor server or by restarting the cell site node a predetermined number of times (e.g., once, twice, etc.) within a predetermined time period (e.g., 30 seconds, one minute, etc.) before finally determining that the vendor certificate cannot be obtained from the vendor server. Failure to obtain the vendor certificate from the vendor server may automatically trigger an alarm, such as an email transmission, an audible sound, or a visible warning light, notifying appropriate personnel that manual intervention may be required to address the problem.

[0112] In some cases, the vendor server may transmit an expired vendor certificate to the cell site node when performing 802 validation of the cell site node, for example, in transmitting 912 the second request in Figure 9. In such cases, the operator certificate acquisition process 1000 in Figure 10 may be performed to enable the cell site node to receive a non-expired vendor certificate from the vendor server.

[0113] Referring again to Figure 8, if the cell site node is verified, the cell site node management process 800 may include establishing 804 a Transport Layer Security (TLS) connection between the cell site node and a central server, e.g., a server of a central management system such as an SMO, e.g., SMO 604 of Figure 6. Generally, establishing 804 a TLS connection between the cell site node and the central server may enable secure communication between the cell site node and the central server. As will be appreciated by those skilled in the art, the TLS connection may be established 804 according to the TLS protocol.

[0114] The cell site node management process 800 may include registering the cell site node with the cellular network (806). Generally, registering the cell site may include the cell site node registering itself with a central server to register itself with the cellular network, thereby enabling the cell site node to communicate over the cellular network.

[0115] Figure 11 is a diagram illustrating an example process 1100 for registering a cell site node with a cellular network (806) in accordance with some implementations of the subject matter of this disclosure. Figure 11 illustrates communication between the cell site node and a central server, shown as SMO in Figure 11. Communication between the cell site node and the central server can be secured, such as by using encryption, such as by using a TLS connection established (804) between the cell site node and the central server, as will be understood by one skilled in the art.

[0116] As shown in FIG. 11 , before the cell site registration process 1100 is initiated, the cell site node has received, for example, an IP address in an ADV message 910 transmitted to the cell site node from the DHCP server during the cell site node's verification process 900, and has received, for example, an IMS URI in a response 914 transmitted to the cell site node from the DHCP server during the cell site node's verification process 900.

[0117] The cell site registration process 1100 may include the cell site node transmitting (1102) registration information to a central server. The registration information may uniquely identify the cell site node, thereby enabling the central server to register the cell site node as a unique node. As shown in FIG. 11, the registration information may include a cell site node serial number, which may uniquely identify the cell site node. The registration information may include additional information to facilitate registration of the cell site node. As also shown in FIG. 11, the registration information may include the cell site node serial number, IMS URI, cell site node part number, cell site node version, cell site node code, cell site node vendor, cell site node MGMT media access account (MAC) address, cell site node current deployment profile, and a site ID identifying the cell site where the cell site node is located. The site ID may include, for example, global positioning satellite (GPS) data, such as the latitude and longitude coordinates of the cell site. In some cases, GPS data may not be available or may not be locked, in which case the site ID can be set to "disabled."

[0118] The central server receives the registration information and, in response, transmits an acknowledgment to the cell site node that the registration information was successfully received (1104). Also, in response to receiving the registration information, the central server authorizes the cell site node's serial number (1106). Authorization (1106) can be performed in a variety of ways, as will be understood by those skilled in the art, such as by using a pre-stored lookup table containing a list of valid device serial numbers.

[0119] In response to the cell site node being authorized, the central server transmits configuration information to the cell site node 1108. Generally, the configuration information indicates a configuration for the cell site node for communication in a wireless communication system, e.g., a wireless communication system that includes an SMO.

[0120] The cell site node receives the configuration information and, in response, authorizes the configuration information, for example, according to a secure communication protocol used for secure communication between the cell site node and the central server (1110). In response to authorizing the configuration information, the cell site node uses the configuration information to configure itself for communication in the wireless communication system. Thus, the cell site node can automatically configure itself for communication in the wireless communication system. As shown in FIG. 11 , the configuration information can include Identity Management (IdM) configuration information. Thus, the cell site node configuring itself using the configuration information can include the cell site node configuring itself as an IdM client using the IdM configuration information, enabling the cell site node to use IdM services in the wireless communication system including the central server. As also shown in FIG. 11 , the configuration information can include Open Bootstrap Framework (OBF) configuration information. Thus, the cell site node configuring itself using the configuration information can include the cell site node configuring itself as an OBF client using the OBF configuration information to provide secure bootstrapping of keys.

[0121] In response to the cell site node being unauthorized, an error handling process may be implemented. The error handling process may address the failure to authorize the cell site node serial number in accordance with the cell site operator's conventional error handling protocols, such as by retrying authorization a predetermined number of times (e.g., one, two, etc.) within a predetermined time period (e.g., 30 seconds, one minute, etc.) and / or rebooting the cell site node a predetermined number of times (e.g., one, two, etc.) within a predetermined time period (e.g., 30 seconds, one minute, etc.) before finalizing a determination of unauthorized. A determination of unauthorized may automatically trigger an alarm, such as an email transmission, an audible tone, a visible warning light, etc., notifying appropriate personnel that manual intervention may be required to address the problem.

[0122] 8, if the cell site node is registered, the cell site node management process 800 may include managing 808 the cell site node infrastructure. Generally, managing 808 the cell site node infrastructure enables the cell site node to operate a cloud infrastructure thereon and enables current versions of time-sensitive and / or real-time RAN applications to operate at the cell site node.

[0123] The cell site node may have software installed therein, e.g., storing the software in the cell site node's memory, as part of the cell site node's manufacturing process. The cell site node may also install software inventory information, which includes a manifest listing the respective versions of one or more software modules of the software. Each of the software modules may correspond to a RAN application. By the time the cell site node is delivered to the cell site, set up as needed, and powered on, one or more of the software modules may be outdated and need to be upgraded to a newer version (or downgraded to an older version), and / or one or more new software modules may become available. Management of the cell site node infrastructure (808) may enable the software installed on the cell site node, e.g., the software modules installed on the cell site node, to be up to date.

[0124] 12a and 12b are diagrams illustrating an example process 1200 for managing 808 cell site node infrastructure according to some implementations of the subject matter of this disclosure. FIGS. 12a and 12b illustrate communication between a cell site node and a central server, shown as SMO, e.g., SMO in FIG. 11 . Communication between the cell site node and the central server can be secured, such as by using encryption, e.g., by using a TLS connection established 804 between the cell site node and the central server, as would be understood by one skilled in the art. Also shown in FIGS. 12a and 12b is a software (SW) image repository (repo) server of the central management system, including the SMO. Thus, the SMO and SW image repository server are communicatively coupled. The SW image repository server stores, e.g., in the memory of the SW image repository server, an inventory manifest file listing software modules and their current versions, and stores, e.g., in the memory of the SW image repository server, software images of current versions of the software modules. The inventory manifest file and SW images are available to SMO for use as further discussed below.

[0125] 12a, the management process 1200 may include the central server checking 1202 a software inventory of the cell site node after the cell site node is registered 806 with the central server. Generally, checking 1202 a software inventory of the cell site node may enable the central server to determine whether software installed on the cell site node is current, for example, whether each of one or more software modules installed on the cell site node is current.

[0126] The central server checking the software inventory of the cell site node (1202) may include the central server transmitting an inventory query request to the cell site node (1204). The cell site node may receive the inventory query request and, in response, transmit software inventory information to the central server (1206). As shown in FIG. 12a, the software inventory information may include a current deployment profile for the cell site node and a manifest listing the respective versions of one or more software modules for the cell site node. As also shown in FIG. 12a, the software inventory information may be transmitted (1206) along with the cell site node's serial number and cell site node's part number, thereby enabling the central server to uniquely associate the software inventory information with the cell site node.

[0127] The central server receives the software inventory information and can determine whether the software of the cell site node, e.g., one or more of the software modules of the cell site node, needs to be upgraded / downgraded. This determination can include the central server comparing the software inventory information (e.g., manifest) received from the cell site node with an inventory manifest file. If it is determined that the software inventory information (e.g., manifest) matches the inventory manifest file, the software is current and does not need to be upgraded / downgraded. If it is determined 1208 that the software inventory information (e.g., manifest) does not match the inventory manifest file, the software is not current and needs to be upgraded / downgraded. In particular, one or more software modules that do not match the inventory manifest file need to be upgraded / downgraded, and the management process 1200 continues.

[0128] If the central server does not receive a response to the inventory query request from the cell site node, an error handling process may be implemented (1210). The error handling process may address the lack of response in accordance with the cell site operator's conventional error handling protocol, such as by the central server reattempting to contact the cell site node a predetermined number of times (e.g., once, twice, etc.) within a predetermined time period (e.g., 30 seconds, one minute, etc.) before finally determining that the cell site node is not responding to the inventory query request. The cell site node's failure to respond to the inventory query request may automatically trigger an alarm, such as an email transmission, an audible sound, or a visible warning light, notifying appropriate personnel that manual intervention may be required to address the problem.

[0129] In some implementations, the central server checking the software inventory of the cell site node (1202) can be omitted from the management process 1200. Instead, the management process 1200 may begin with the central server transmitting download instructions to the cell site node (1212), as discussed further below. Omitting the check of the software inventory of the cell site node (1202) may conserve network bandwidth and processing resources at the central server and the cell site node. Because versions of one or more software modules may be changed frequently (e.g., to address identified bugs, improve functionality, account for new functionality, or take advantage of improved technologies in one or more aspects of the wireless communications system), omitting the check of the software inventory of the cell site node (1202) may result in omitting unnecessary transmissions (1204, 1206) and associated processing at the cell site node and central server, as it may be more likely that the management process 1200 will not need to continue, at least in some instances.

[0130] Whether or not the management process 1200 includes checking the software inventory of the cell site node (1202), the management process 1200 can include the central server transmitting download instructions to the cell site node (1212). The download instructions can include an inventory manifest file. The download information can also include unique identification information that uniquely identifies the cell site node. As shown in FIG. 12a, the information that uniquely identifies the cell site node can include the cell site node's serial number, which the central server may have previously received from the cell site node in transmitting registration information to the central server (1120).

[0131] The cell site node can receive the download command and, in response, verify that the received unique identification information uniquely identifies the cell site node, thereby verifying that the download command is an authentic command for the cell site node. If the download command is an authentic command for the cell site node, the cell site node can compare the received inventory management file with software inventory information stored at the cell site node to determine whether the received inventory management file matches the software inventory information (1214). If it is determined that the software inventory information (e.g., its manifest) matches the inventory manifest file, the software at the cell site node is current and does not need to be upgraded / downgraded, and the management process 1200 can proceed to a first loop process 1216. If it is determined that the software inventory information (e.g., its manifest) does not match the inventory manifest file, the software at the cell site node is not current and needs to be upgraded / downgraded. In particular, one or more software modules that do not match the inventory manifest file need to be upgraded / downgraded, and the management process 1200 continues with the cell site node downloading 1214 SW images from a central server, e.g., downloading SW images stored in a SW image repository server accessible to the central server, for one or more software modules that are determined to not match the inventory manifest file. The management process 1200 can then proceed to a first loop process 1216.

[0132] Generally, the first loop process 1216 may enable the central server to monitor the cell site node's response to the transmitted 1212 download command. The first loop process 1216 may include the central server transmitting 1218 a status query to the cell site node inquiring about the status of the response to the transmitted 1212 download command. As shown in FIG. 12a, the status query may include information uniquely identifying the cell site node, including the cell site node's serial number, which the central server may have previously received from the cell site node in transmitting 1120 registration information to the central server.

[0133] The cell site node may receive the status query and, in response, verify that the status query is a genuine query for the cell site node by verifying that the received unique identification information uniquely identifies the cell site node. If the status query is a genuine query for the cell site node, the cell site node may determine 1220 a status of the response to the transmitted 1212 download command and transmit 1222 the determined status to the central server. The determined 1220 status may be that a software upgrade / downgrade is not required, the determined 1220 status may be that the software upgrade / downgrade can proceed successfully, or the determined 1220 status may be that the software upgrade / downgrade failed.

[0134] The first loop process 1216 of the management process 1200 may be periodically executed according to a predetermined time schedule preset in the central server, for example, the central server transmits a status query (1218) according to the predetermined time schedule as long as the cell site node continues to respond that the software upgrade / downgrade is proceeding normally.

[0135] If it is determined 1220 that the software upgrade / downgrade failed due to a failure to download one or more required SW images from the central server, the cell site node may transmit 1224 a download failure notification to the central server. The download failure notification may include an indication of the failure status, an identification of the one or more SW images that could not be downloaded, unique identification information that uniquely identifies the cell site node, including the cell site node's serial number, and a reason for the failure (e.g., file not found or timed out).

[0136] The central server may receive the download failure notification and, in response, verify that the download failure notification is a genuine notification from the cell site node by verifying that the received unique identification information uniquely identifies the cell site node. If the download failure notification is a genuine notification from the cell site node, an error handling process may be implemented (1226). The error handling process may address the failure in accordance with the cell site operator's conventional error handling protocol, such as by the central server attempting to transmit the undownloadable SW image or images identified in the notification a predetermined number of times (e.g., once, twice, etc.) within a predetermined time period (e.g., 30 seconds, one minute, etc.) before finally determining that a failure has occurred. The failure may automatically trigger an alarm, such as an email transmission, an audible sound, or a visible warning light, notifying appropriate personnel that manual intervention may be required to address the problem.

[0137] If it is determined that the software upgrade / downgrade can proceed normally (1220), the cell site node may transmit a successful download notification to the central server (1228). The successful download notification may include an indication of the success status, an identification of one or more SW images required for the upgrade / downgrade, and unique identification information that uniquely identifies the cell site node, including the cell site node's serial number.

[0138] The central server receives the successful download notification and, in response, can verify that the successful download notification is an authentic notification from the cell site node by verifying that the received unique identification information uniquely identifies the cell site node. If the successful download notification is an authentic notification from the cell site node, the central server can either immediately transmit (1230) an installation request to the cell site node or transmit (1239) the installation request at a later time, such as during a scheduled maintenance window for the cell site node. Transmitting (1230) the installation request immediately may help ensure that the current software is installed at the cell site node as soon as possible. Transmitting (1230) the installation request during a scheduled maintenance window may help prevent the cell site node from experiencing excessive downtime due to software upgrades / downgrades. Whether transmitted immediately (1230) or later (1230), the installation request may include unique identification information that uniquely identifies the cell site node, including the cell site node's serial number, and may include one or more SW images identified in the download success notification.

[0139] The cell site node may receive the installation request and, in response, verify that the installation request is a genuine request from the central server by verifying that the received unique identification information uniquely identifies the cell site node. If the installation request is a genuine notification from the cell site node, the cell site node may initiate (1232) the installation of the received one or more SW images. The received one or more SW images may be installed in an order predefined in the installation request, as shown in FIG. 12b by the installation request providing an alphabetical installation order for the three SW images as a, b, and c. In response to the successful installation of the received SW images, the cell site node may update (1232) its software inventory information to reflect the current versions of the updated SW modules.

[0140] After transmitting 1230 the installation request, management process 1200 may include performing a second loop process 1234. Generally, second loop process 1234 may enable the central server to monitor the cell site node's response to the transmitted 1230 installation request. Second loop process 1234 may include the central server transmitting 1236 a status query to the cell site node inquiring about the status of the response to the transmitted 1230 installation request. As shown in FIG. 12b, the installation request may include information uniquely identifying the cell site node, including the cell site node's serial number, which the central server may have previously received from the cell site node in transmitting 1228 a successful download notification to the central server.

[0141] The cell site node can receive the status query and, in response, verify that the status query is a genuine query for the cell site node by verifying that the received unique identification information uniquely identifies the cell site node. If the status query is a genuine query for the cell site node, the cell site node can determine 1238 a status of the response to the transmitted 1230 installation request and transmit 1240 the determined status to the central server. The determined 1238 status can be that the software installation can proceed normally, or the determined 1238 status can be that the software installation failed.

[0142] The second loop process 1234 of the management process 1200 may be periodically executed according to a predetermined time schedule preset in the central server, for example, the central server transmits a status query (1236) according to the predetermined time schedule as long as the cell site node continues to respond that the software installation is proceeding normally.

[0143] If it is determined that the software installation failed because the received SW image(s) could not be installed at the cell site node (1238), the cell site node may transmit an installation failure notification to the central server (1242). The installation failure notification may include an indication of the failure status, an identification of the SW image(s) that could not be installed, unique identification information that uniquely identifies the cell site node, including the cell site node's serial number, and a reason for the failure (e.g., an error string generated during the installation attempt).

[0144] The cell site node may continue to use the previously installed version of each software module that failed to install. However, if the software module that failed to install is a critical software module, for example, a software module for a critical infrastructure function, the cell site node may reboot to recover from the condition that caused the failure, thereby successfully installing the one or more SW images that failed to install after the reboot. An example of a critical infrastructure function is the Juniper Cloud-Native Router (JCNR). Another example of a critical infrastructure function is the VAULT function.

[0145] The central server may receive the installation failure notification and, in response, verify that the installation failure notification is a genuine notification from the cell site node by verifying that the received unique identification information uniquely identifies the cell site node. If the installation failure notification is a genuine notification from the cell site node, an error handling process may be implemented (1244). The error handling process may address the failure in accordance with the cell site operator's conventional error handling protocol, such as by automatically triggering an alarm, such as an email transmission, an audible sound, a visible warning light, or the like, notifying appropriate personnel that manual intervention may be required to address the problem.

[0146] If it is determined 1238 that the software installation can proceed normally, the cell site node may transmit 1246 a successful installation notification to the central server. The successful installation notification may include an indication of the success status, an identification of the installed SW image or images, and unique identification information that uniquely identifies the cell site node, including the cell site node's serial number.

[0147] The central server may receive the successful installation notification and, in response, verify that the successful installation notification is an authentic notification from the cell site node by verifying that the received unique identification information uniquely identifies the cell site node. If the successful installation notification is an authentic notification from the cell site node, the central server may consider the installation successful and the cell site node management process 800 may continue.

[0148] 8, after managing the cell site node infrastructure (808), the cell site node management process 800 may include provisioning the cell site infrastructure (810). Generally, provisioning the cell site infrastructure (810) may enable the cell site infrastructure to be properly configured to operate at the cell site node in order for the cell site node to properly communicate over a wireless communication system.

[0149] Figure 13 is a diagram illustrating an example process 1300 for provisioning (810) cell site infrastructure in accordance with some implementations of the subject matter of this disclosure. Figure 13 illustrates communication between a cell site node and a central server, shown as SMO, e.g., SMO in Figures 11, 12a, and 12b. Communication between the cell site node and the central server can be secured, such as by using encryption, such as by using a TLS connection established (804) between the cell site node and the central server, as will be understood by those skilled in the art.

[0150] As shown in Figure 13, the provisioning process 1300 can include the central server transmitting (1302) an infrastructure configuration request to the cell site node after the cell site node has been registered (806) with the central server and after the cell site node's infrastructure has been managed (808). As shown in Figure 13, the infrastructure configuration request can include information uniquely identifying the cell site node, including the cell site node's serial number, a deployment profile for the cell site node, and infrastructure configuration information that the central server may have previously received from the cell site node (e.g., in transmitting (1120) the registration information to the central server and / or during the management process 1200).

[0151] The cell site node may receive the infrastructure configuration request and, in response, verify that the received unique identification information uniquely identifies the cell site node, thereby verifying that the infrastructure configuration request is an authentic request for the cell site node. If the infrastructure configuration request is an authentic request for the cell site node, the cell site node may use the received infrastructure configuration information to configure the cell site node's infrastructure according to the received deployment profile (1304), and the cell site node may transmit an infrastructure configuration response to the central server (1306). The infrastructure configuration response may include information uniquely identifying the cell site node, including the cell site node's serial number, the status of the infrastructure configuration, and, if the infrastructure configuration failed, a reason for the failure. If either the received deployment profile or the received infrastructure configuration information is irrelevant to the cell site node, the infrastructure configuration response may include information indicating the irrelevant deployment profile and / or infrastructure configuration information.

[0152] The central server can receive the infrastructure configuration response and, in response, verify that the received unique identification information uniquely identifies the cell site node, thereby verifying that the infrastructure configuration response is an authentic response from the cell site node. If the infrastructure configuration response is an authentic response from the cell site node, the central server can transmit (1308) hardware monitoring configuration information to the cell site node. The hardware monitoring configuration information can include information uniquely identifying the cell site node, including the cell site node's serial number, and can include software configuration files to be applied to the cell site node. As shown in FIG. 13, examples of hardware monitoring configuration information include a small form-factor pluggable (SFP) monitor configured to monitor the cell site node's SFP, a memory monitor configured to monitor the cell site node's memory, a power monitor configured to monitor at least one port of the cell site node, and a storage monitor configured to monitor available storage at the cell site node.

[0153] The cell site node can receive the hardware monitoring configuration information and, in response, verify that the received unique identification information uniquely identifies the cell site node, thereby verifying that the hardware monitoring configuration information is authentic information about the cell site node. If the hardware monitoring configuration information is authentic information about the cell site node, the cell site node can apply the hardware monitoring configuration information to the cell site node (1310), and the cell site node can transmit a hardware monitoring configuration response to the central server (1312). The hardware monitoring configuration response can include information uniquely identifying the cell site node, including the serial number of the cell site node, the status of the hardware monitoring configuration, and, if the hardware monitoring configuration failed, a reason for the failure.

[0154] The central server can receive the hardware monitoring configuration response and, in response, verify that the hardware monitoring configuration response is an authentic response from the cell site node by verifying that the received unique identification information uniquely identifies the cell site node. If the hardware monitoring configuration response is an authentic response from the cell site node, the central server can perform periodic inventory queries, e.g., manage the cell site node infrastructure (808), as discussed above.

[0155] In some implementations, the subject matter of this disclosure can be configured to be implemented within a system 1400, as shown in FIG. 14 . The system 1400 can include one or more of a processor 1410, a memory 1420, a storage device 1430, and an input / output device 1440. Each of the components 1410, 1420, 1430, and 1440 can be interconnected using a system bus 1450. The processor 1410 can be configured to process instructions for execution within the system 1400. In some implementations, the processor 1410 can be a single-threaded processor. In alternative implementations, the processor 1410 can be a multi-threaded processor. The processor 1410 can be further configured to process instructions stored in the memory 1420 or on the storage device 1430, including receiving or transmitting information through the input / output device 1440. The memory 1420 can store information within the system 1400. In some implementations, memory 1420 may be a computer-readable medium. In alternative implementations, memory 1420 may be a volatile memory unit. In further implementations, memory 1420 may be a non-volatile memory unit. Storage device 1430 may be capable of providing mass storage for system 1400. In some implementations, storage device 1430 may be a computer-readable medium. In alternative implementations, storage device 1430 may be a floppy disk device, a hard disk device, an optical disk device, a tape device, a non-volatile solid-state memory, or any other type of storage device. Input / output device 1440 may be configured to provide input / output operations for system 1400. In some implementations, input / output device 1440 may include a keyboard and / or a pointing device. In alternative implementations, input / output device 1440 may include a display unit for displaying a graphical user interface.

[0156] 15 is a diagram illustrating an example method 1500 for managing cell sites in a wireless access network in accordance with some implementations of the subject matter of this disclosure. Method 1500 can be implemented, for example, using the implementations shown in and described with respect to FIGS. 6-13.

[0157] The method 1500 includes transmitting 1502 a first certificate (e.g., a vendor certificate) pre-installed on the cell site node from a cell site node (e.g., a distributed unit such as the DU 304 of FIG. 3, the DUs 508, 510 of FIGS. 5a-5c, or the DUs 602a, 602b, 602n of FIG. 6) to a first server (e.g., the DHCP server of FIG. 9) in the wireless communication system. The method 1500 also includes receiving 1504 a second certificate (e.g., a CA root certificate) at the cell site node from the first server after transmitting 1502 the first certificate. Method 1500 also includes transmitting 1506 the second certificate from the cell site node to a central server (e.g., a server of a central management system, such as an SMO, e.g., SMO 604 of FIG. 6 or an SMO of FIGS. 11-13), and receiving 1508 configuration information at the cell site node from the central server after transmitting the second certificate. The configuration information indicates a configuration of the cell site node for communication in the wireless communication system. Upon receiving the configuration information, the cell site node uses the configuration information to automatically configure itself for communication in the wireless communication system.

[0158] In some implementations, the subject matter of this disclosure can include one or more of the following additional features.

[0159] In some implementations, the method of the present disclosure may also include transmitting software inventory information from the cell site node to the central server after the cell site node configures itself, and installing updated software on the cell site node in response to the central server determining that software installed on the cell site node has expired based on the software inventory information. Furthermore, the central server may be configured to trigger installation of the updated software at any time after the cell site node configures itself. In response to the central server determining that software installed on the cell site node has expired based on the software inventory information, the cell site node may receive installation instructions from the central server, where the installation instructions may cause the cell site node to automatically download updated software to be installed on the cell site node, and / or the software inventory information may include a manifest listing the respective versions of one or more software modules required by the cell site node. Furthermore, installing the updated software on the cell site node may include downloading software for each of the one or more software modules from the central server and installing the downloaded software on the cell site node.

[0160] In some implementations, the cell site node may transmit software inventory information from the cell site node to the central server to maintain a current software inventory on the cell site node. Further, the software inventory information may include a manifest listing respective versions of one or more software modules required by the cell site node, and the method may further include, after transmitting the software inventory information, receiving updated configuration information from the central server at the cell site node indicating an updated configuration for at least one software module identified in the software inventory information, and upon receiving the updated configuration information, causing the cell site node to automatically configure the at least one software module using the updated configuration information. Furthermore, the cell site node transmitting the software inventory information may be triggered by the cell site node initially registering with the central server.

[0161] In some implementations, the first server may transmit the second certificate to the cell site node after the first server has approved the first certificate received from the cell site node, and the central server may transmit the configuration information to the cell site node after the central server has approved the second certificate received from the cell site node.

[0162] In some implementations, the cell site node receiving the second certificate may automatically trigger the cell site node to transmit the second certificate from the cell site node to the central server.

[0163] In some implementations, a pre-installed agent on the cell site node may cause at least one of transmitting the first certificate, transmitting the second certificate, and the cell site node configuring itself with the configuration information.

[0164] In some implementations, the transmission of the first certificate may be automatically triggered by powering on the cell site node.

[0165] In some implementations, the central server may be configured to update the configuration of a cell site node any time after the cell site node configures itself.

[0166] In some implementations, the cell site node that configures itself may include the cell site node that configures itself to operate a cloud infrastructure locally on the cell site node.

[0167] In some implementations, a wireless communication system may include a radio access network (RAN).

[0168] In some implementations, the cell site nodes may communicate with base stations in a wireless communication system. Further, the base stations may include at least one of an eNodeB base station, a gNodeB base station, a wireless base station, and any combination thereof. Further, the base stations may operate in at least one of a Long Term Evolution communication system, a new radio (NR) communication system, and any combination thereof.

[0169] In some implementations, the cell site node may be a distributed unit (DU).

[0170] In some implementations, the central server may be a server of a central management system.

[0171] The systems and methods disclosed herein can be embodied in various forms, including, for example, data processors such as computers that also include databases, digital electronic circuitry, firmware, software, or combinations thereof. Furthermore, the above-described features and other aspects and principles of implementations of the present disclosure can be implemented in a variety of environments. Such environments and related applications can be specially constructed to perform the various processes and operations in accordance with the disclosed implementations, or they can include general-purpose computers or computing platforms selectively activated or reconfigured by code to provide the required functionality. The processes disclosed herein are not inherently related to any particular computer, network, architecture, environment, or other apparatus, but can be implemented by any suitable combination of hardware, software, and / or firmware. For example, various general-purpose machines can be used with programs written in accordance with the teachings of the disclosed implementations, or it may be more convenient to construct specialized apparatus or systems to perform the required methods and techniques.

[0172] The systems and methods disclosed herein can be implemented as a computer program product, i.e., a computer program tangibly embodied in an information carrier, e.g., in a machine-readable storage device or in a propagated signal, for execution by or to control the operation of a data processing apparatus, e.g., a programmable processor, computer, or multiple computers. The computer program can be written in any type of programming language, including compiled or interpreted languages, and can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. The computer program can be deployed to run on one computer, on multiple computers at one site, or on multiple computers distributed across multiple sites and interconnected by a communications network.

[0173] As used herein, the term "user" can refer to any entity, including a person or a computer.

[0174] Although ordinal numbers such as first, second, etc. may relate to order in some circumstances, as used in this document, ordinal numbers do not necessarily imply order. For example, ordinal numbers may be used simply to distinguish one item from another. For example, distinguishing a first event from a second event need not imply any chronological order or fixed frame of reference (just as a first event in one paragraph of this description may differ from a first event in another paragraph of this description).

[0175] The foregoing description is intended to illustrate, but not to limit, the scope of the invention, which is defined by the appended claims. Other implementations are also within the scope of the following claims.

[0176] These computer programs, which may also be referred to as programs, software, software applications, applications, components, or code, include machine instructions for a programmable processor and may be implemented in a high-level procedural and / or object-oriented programming language and / or in assembly / machine language. As used herein, the term "machine-readable medium" refers to any computer program product, apparatus, and / or device used to provide machine instructions and / or data to a programmable processor, such as, for example, magnetic disks, optical disks, memories, and programmable logic devices (PLDs), including machine-readable media that receive machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor. A machine-readable medium may store such machine instructions non-transitoryly, such as, for example, a non-transitory solid-state memory or a magnetic hard drive, or any equivalent storage medium. Alternatively or additionally, the machine-readable medium may temporarily store such machine instructions, such as, for example, a processor cache or other random access memory associated with one or more physical processor cores.

[0177] To provide for interaction with a user, the subject matter described herein can be implemented on a computer having a display device, such as, for example, a cathode ray tube (CRT) or liquid crystal display (LCD) monitor, for displaying information to a user, and a keyboard and pointing device, such as, for example, a mouse or trackball, by which the user can provide input to the computer. Other types of devices can also be used to provide for interaction with a user. For example, feedback provided to the user can be any form of sensory feedback, such as, for example, visual feedback, auditory feedback, or tactile feedback, and input from the user can be received in any form, including, but not limited to, acoustic input, speech input, or tactile input.

[0178] The subject matter described herein can be implemented within a computing system that includes back-end components, such as, for example, one or more data servers, or middleware components, such as, for example, one or more application servers, or front-end components, such as, for example, one or more client computers having a graphical user interface or web browser through which a user can interact with an implementation of the subject matter described herein, or any combination of such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication, such as, for example, a communication network. Examples of communication networks include, but are not limited to, a local area network (LAN), a wide area network (WAN), and the Internet.

[0179] A computing system may include clients and servers. Clients and servers are generally, though not exclusively, remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on respective computers and having a client-server relationship to each other.

[0180] The implementations set forth in the foregoing description do not represent all implementations consistent with the subject matter described herein. Rather, they are merely some examples consistent with aspects related to the described subject matter. While several variations have been described in detail above, other modifications or additions are possible. In particular, further features and / or variations may be provided in addition to those described herein. For example, the implementations described above may be directed to various combinations and subcombinations of the disclosed features and / or combinations and subcombinations of certain additional features disclosed above. In addition, the logic flow depicted in the accompanying drawings and / or described herein does not necessarily require the particular order shown, or sequential order, to achieve desirable results. Other implementations are possible within the scope of the following claims.

Claims

1. 1. A computer-implemented method comprising: transmitting a first certificate pre-installed on a cell site node from the cell site node to a first server within a wireless communication system; receiving a second certificate at the cell site node from the first server after transmitting the first certificate; transmitting the second certificate from the cell site node to a central server; receiving configuration information at the cell site node from the central server after transmitting the second certificate, the configuration information indicating a configuration for the cell site node for communication in the wireless communication system; A computer-implemented method that, upon receiving the configuration information, causes the cell site node to automatically configure itself using the configuration information for communication in the wireless communications system.

2. transmitting software inventory information from the cell site node to the central server after the cell site node configures itself; installing updated software at the cell site node in response to the central server determining based on the software inventory information that software installed at the cell site node has expired; The computer-implemented method of claim 1 further comprising:

3. the cell site node receives an installation instruction from the central server in response to the central server determining based on the software inventory information that software installed at the cell site node has expired; The computer-implemented method of claim 2 , wherein the installation instructions cause the cell site node to automatically download the updated software to be installed at the cell site node.

4. The central server is configured to trigger installation of the updated software any time after the cell site node has configured itself. The computer-implemented method of claim 2 .

5. 3. The computer-implemented method of claim 2, wherein the cell site node transmits the software inventory information from the cell site node to the central server to maintain a current software inventory on the cell site node.

6. the software inventory information includes a manifest listing the respective versions of one or more software modules required by the cell site node; The computer-implemented method further includes, after transmitting the software inventory information, receiving updated configuration information at the cell site node from the central server, the updated configuration information indicating an updated configuration for at least one software module identified in the software inventory information; 6. The computer-implemented method of claim 5, wherein upon receiving the updated configuration information, the cell site node automatically configures the at least one software module using the updated configuration information.

7. the first server transmits the second certificate to the cell site node after authorizing the first certificate received from the cell site node; 5. The computer-implemented method of claim 1, wherein the central server transmits the configuration information to the cell site node after the central server approves the second certificate received from the cell site node.

8. 5. The computer-implemented method of claim 1, wherein the cell site node receiving the second certificate automatically triggers the cell site node to transmit the second certificate from the cell site node to the central server.

9. 5. The computer-implemented method of claim 1, wherein a pre-installed agent on the cell site node causes at least one of transmitting the first certificate, transmitting the second certificate, and the cell site node configuring itself using the configuration information.

10. The computer-implemented method of claim 1 , wherein transmission of the first certificate is automatically triggered by powering on the cell site node.

11. 5. The computer-implemented method of claim 1, wherein the central server is configured to update the configuration of the cell site node any time after the cell site node has configured itself.

12. The computer-implemented method of claim 1 , wherein the cell site node configures itself to operate a cloud infrastructure locally on the cell site node.

13. The computer-implemented method of claim 1 , wherein the wireless communication system includes a radio access network (RAN).

14. 5. The computer-implemented method of claim 1, wherein the cell site node is in communication with a base station in the wireless communication system.

15. 15. The computer-implemented method of claim 14, wherein the base station comprises at least one of an eNodeB base station, a gNodeB base station, a wireless base station, and any combination thereof.

16. 16. The computer-implemented method of claim 15, wherein the base station operates in at least one of a Long Term Evolution communication system, a new radio (NR) communication system, and any combination thereof.

17. The computer-implemented method of any one of claims 1 to 4, wherein the cell site node is a distributed unit (DU).

18. The computer-implemented method of claim 1 , wherein the central server is a server of a central management system.

19. 1. An apparatus for performing an operation, comprising: The operation is transmitting a first certificate pre-installed in a cell site node from the cell site node to a first server within a wireless communication system; receiving a second certificate at the cell site node from the first server after transmitting the first certificate; transmitting the second certificate from the cell site node to a central server; receiving configuration information at the cell site node from the central server after transmitting the second certificate; the configuration information indicates a configuration for the cell site node for communication in the wireless communication system; and an apparatus for, upon receiving the configuration information, causing the cell site node to automatically configure itself for communication in the wireless communications system using the configuration information.

20. A computer program comprising instructions, The instructions, when executed by at least one processor, cause the at least one processor to perform operations, the operations including: transmitting a first certificate pre-installed in a cell site node from the cell site node to a first server within a wireless communication system; receiving a second certificate at the cell site node from the first server after transmitting the first certificate; transmitting the second certificate from the cell site node to a central server; receiving configuration information at the cell site node from the central server after transmitting the second certificate, the configuration information indicating a configuration for the cell site node for communication in the wireless communication system; A computer program product that, upon receiving the configuration information, causes the cell site node to automatically configure itself for communication in the wireless communications system using the configuration information.

Citation Information

Patent Citations

  • Third generation partnership project (3GPP) plug and play (PNP) operation in a hybrid open radio access network (o-ran) environment

    US20210314211A1