Method and arrangement for validation of a certificate in a communication network

The centralized OCVP protocol addresses the complexity and security risks in telecom networks by validating certificates through a server, simplifying operations and ensuring zero trust compliance, thus enhancing network security and efficiency.

WO2025174275A1PCT designated stage Publication Date: 2025-08-21TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2024/050117
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-12
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

The increasing complexity of telecom networks due to diverse trust domains, network slicing, and disaggregation of RAN functions leads to operational and maintenance challenges in standard PKI systems, with potential security risks from accidental or malicious installation of trusted certificates, and existing blockchain-based decentralized PKI solutions are not yet consolidated for widespread deployment.

Method used

A method and system for centralized certificate validation using an Online Certificate Validation Protocol (OCVP) that allows clients to request validation from a server, which checks the certificate's trust domain and revocation status, eliminating the need for pre-installed peer certificates and enhancing security by integrating with existing protocols like TLS and IKE.

Benefits of technology

This approach simplifies network operations and maintenance, improves security by avoiding weak PKI configurations, and ensures zero trust compliance by centralizing certificate validation, reducing the risk of accidental or malicious certificate additions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050117_21082025_PF_FP_ABST
    Figure SE2024050117_21082025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments herein relate to, for example, a method performed by a client (110) for handling communication in a communication network. The client (110) transmits a validation request to a server (13), wherein the validation request comprises: a client identity allowing the server (13) to identify a PKI entity associated to the client (110), an indication of a certificate to be validated, and a client authentication data, for allowing the server (13) to validate the validation request. The client (110) further receives a response from the server (13), wherein the response indicates validation or rejection of the validation request.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD AND ARRANGEMENT FOR VALIDATION

[0002] OF A CERTIFICATE IN A COMMUNICATION NETWORK

[0003] TECHNICAL FIELD

[0004] Embodiments herein relate to a client, a server, and methods performed therein for communication. Furthermore, a computer program and a computer readable storage medium are also provided herein. In particular, embodiments herein relate to secure communication in a communication network.

[0005] BACKGROUND

[0006] In a typical communication network, user equipments (UE), also known as communication devices, wireless communication devices, mobile stations, stations (STA) and / or wireless devices, communicate via for example an access network (AN) such as a radio access network (RAN) with one or more core networks (CN). The RAN covers a geographical area which is divided into service areas or cell areas, with each service area or cell area being served by radio network node such as an access node e.g. a Wi-Fi access point or a radio base station (RBS), which in some networks may also be called, for example, a NodeB, a gNodeB, or an eNodeB. The service area or cell area is a geographical area where radio coverage is provided by the radio network node. The radio network node operates on radio frequencies to communicate over an air interface with the UEs within range of the radio network node. The radio network node communicates over a downlink (DL) to the UE and the UE communicates over an uplink (UL) to the radio network node.

[0007] A Universal Mobile Telecommunications System (UMTS) is a third generation telecommunications network, which evolved from the second generation (2G) Global System for Mobile Communications (GSM). The UMTS terrestrial radio access network (UTRAN) is essentially a RAN using wideband code division multiple access (WCDMA) and / or High-Speed Packet Access (HSPA) for communication with user equipment. In a forum known as the Third Generation Partnership Project (3GPP), telecommunications suppliers propose and agree upon standards for present and future generation networks and UTRAN specifically, and investigate enhanced data rate and radio capacity. In some RANs, e.g. as in UMTS, several radio network nodes may be connected, e.g., by landlines or microwave, to a controller node, such as a radio network controller (RNC) or a base station controller (BSC), which supervises and coordinates various activities of the plural radio network nodes connected thereto. The RNCs are typically connected to one or more core networks.

[0008] Specifications for the Evolved Packet System (EPS) have been completed within the 3GPP and this work continues in the coming 3GPP releases, such as 5G, for example New Radio (NR), and beyond networks. The EPS comprises the Evolved Universal Terrestrial Radio Access Network (E-UTRAN), also known as the Long-Term Evolution (LTE) radio access network, and the Evolved Packet Core (EPC), also known as System Architecture Evolution (SAE) core network. E-UTRAN / LTE is a 3GPP radio access technology wherein the radio network nodes are directly connected to the EPC core network. As such, the Radio Access Network (RAN) of an EPS has an essentially “flat” architecture comprising radio network nodes connected directly to one or more core networks.

[0009] With the 5G technologies such as NR, focus is on a set of features such as the use of very many transmit- and receive-antenna elements that makes it possible to utilize beamforming, such as transmit-side and receive-side beamforming. Transmit-side beamforming means that the transmitter can amplify the transmitted signals in a selected direction or directions, while suppressing the transmitted signals in other directions. Similarly, on the receive-side, a receiver can amplify signals from a selected direction or directions.

[0010] Telecom networks are widely using Public Key Infrastructure (PKI) public key certificates for authentication and secure communication using Transport Layer Security (TLS) and Internet Key Exchange (IKE) protocols. These solutions may use a certificate, such as an X.509 certificate, that binds an identity to a public key using a digital signature. The certificate contains an identity, a hostname, or an organization, or an individual, and a public key.

[0011] Telecom networks are becoming increasingly complex, owing to diverse and demanding use cases, increased virtualization, network slicing, as well as the ongoing disaggregation and distribution of the RAN functions, including shared network with multivendor, each one with its own PKI System.

[0012] This requires a stricter trust domain segregation on both TLS and IKE protocols, while suppressing unwanted signals from other directions.

[0013] SUMMARY

[0014] As a part of developing embodiments herein one or more of the following problems were identified: Due to the network evolution the operational and maintenance activity on a standard PKI system is increased, mainly considering the different trust domains, and the consequent activity required on each single network component to be zero trust compliant.

[0015] In addition, to authenticate the peer certificate, the involved entity or network element requires to have preinstalled the public keys of the peer's certificate authorities. This can expose the entity to security risks if in case trusted certificates that are not required are installed accidentally or due to a malicious user or in case the software component requires an overset of the minimal trusted certificates.

[0016] Emerging technologies like blockchain-based decentralized PKI are a significant trend for PKI technology that can solve these issues, but these are not enough consolidated for a massive usage / deployment.

[0017] An object herein is to handle communication in a secure and efficient manner.

[0018] According to an aspect the object is achieved by providing a method performed by a client for handling communication in a communication network. The client transmits a validation request to a server, wherein the validation request comprises: a client identity allowing the server to identify a PKI entity associated to the client, an indication of a certificate to be validated, and a client authentication data, for allowing the server to validate the validation request. The client receives a response from the server, wherein the response indicates validation or rejection of the validation request.

[0019] According to another aspect the object is achieved by providing a method performed by a server for handling communication in a communication network. The server receives a validation request from a client, wherein the validation request comprises: a client identity allowing the server to identify a PKI entity associated to the client, an indication of a certificate to be validated, and a client authentication data, for allowing the server to validate the validation request. The server checks that a domain of the certificate is in a trusted domains list of the PKI entity associated to the client; and checks whether the certificate has been revoked or not in a certificate revocation list. The server then responds with a response indicating validation or rejection of the validation request based the previous checks.

[0020] It is furthermore provided herein a computer program comprising instructions, which, when executed on at least one processor, cause the at least one processor to carry out any of the methods above, as performed by the server and the client, respectively. It is additionally provided herein a computer-readable storage medium, having stored thereon a computer program comprising instructions which, when executed on at least one processor, cause the at least one processor to carry out the method according to any of the methods above, as performed by the server and the client, respectively.

[0021] According to another aspect a server and a client are herein provided to be configured to perform the methods herein, respectively.

[0022] Thus, according to an aspect the object is achieved by providing a client for handling communication in a communication network. The client is configured to transmit a validation request to a server, wherein the validation request comprises: a client identity allowing the server to identify a PKI entity associated to the client, an indication of a certificate to be validated, and a client authentication data, for allowing the server to validate the validation request. The client is further configured to receive a response from the server, wherein the response indicates validation or rejection of the validation request.

[0023] According to another aspect the object is achieved by providing a server for handling communication in a communication network. The server is configured to receive a validation request from a client, wherein the validation request comprises: a client identity allowing the server to identify a PKI entity associated to the client, an indication of a certificate to be validated, and a client authentication data, for allowing the server to validate the validation request. The server is further configured to check that a domain of the certificate is in a trusted domains list of the PKI entity associated to the client; and check whether the certificate has been revoked or not in a certificate revocation list. The server is configured to then respond with a response indicating validation or rejection of the validation request based the previous checks.

[0024] Embodiments disclose a validation request with which the client demands a certificate validation from the server without a need to have previously installed public keys of the peer's certificate authorities. The server will perform validation based on a domain of the certificate and also perform a revocation check.

[0025] The protocol may extend existing certificate authentication protocols like TLS and IKE to have a centralized peer X.509 certificate validation, which validation includes the certificate revocation check.

[0026] The validation response from the server may then be cached into the client to minimize the network overhead.

[0027] Embodiments herein may allow a centralized certificate validation process simplifying the operational and maintenance activities on the network, avoiding manual trusted certificates distribution on each single network device. The overall security level may be improved in a complex network avoiding cases where some network devices can be configured with weaker PKI security constraints, for example, Certificate Revocation List (CRL) check disabled, or with some additional trusted certificates accidentally or maliciously added, bypassing the trust domain segregation and zero trust compliance.

[0028] BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Embodiments will now be described in more detail in relation to the enclosed drawings, in which:

[0030] Fig. 1 is a schematic overview depicting a communication network according to embodiments herein;

[0031] Fig. 2 shows a combined flowchart and signalling scheme according to some embodiments herein;

[0032] Fig. 3 is a schematic flowchart depicting a method performed by a client according to embodiments herein;

[0033] Fig. 4 is a schematic flowchart depicting a method performed by a server according to embodiments herein;

[0034] Fig. 5 is a schematic flowchart depicting methods according to some embodiments herein;

[0035] Fig. 6 is a schematic flowchart depicting methods according to some embodiments herein;

[0036] Fig. 7 is a schematic flowchart depicting methods according to some embodiments herein;

[0037] Fig. 8 is a block diagram depicting a client according to embodiments herein;

[0038] Fig. 9 is a block diagram depicting a server according to embodiments herein;

[0039] Fig. 10 shows an example of a communication system QQ100 in accordance with some embodiments;

[0040] Fig. 11 shows a UE QQ200 in accordance with some embodiments;

[0041] Fig. 12 shows a network node QQ300 in accordance with some embodiments;

[0042] Fig. 13 is a block diagram of a host QQ400, which may be an embodiment of the host QQ116 of Fig. 10, in accordance with various aspects described herein;

[0043] Fig. 14 is a block diagram illustrating a virtualization environment QQ500 in which functions implemented by some embodiments may be virtualized; and

[0044] Fig. 15 shows a communication diagram of a host QQ602 communicating via a network node QQ604 with a UE QQ606 over a partially wireless connection in accordance with some embodiments. DETAILED DESCRIPTION

[0045] Embodiments herein relate to communication networks in general. Fig. 1 is a schematic overview depicting a communication network 1. The communication network 1 comprises one or more ANs and one or more CNs. The communication network 1 may use a number of different technologies, such as wired or wireless technology, Wi-Fi, Long Term Evolution (LTE), LTE-Advanced, NR, Wideband Code Division Multiple Access (WCDMA), Global System for Mobile communications / Enhanced Data rate for GSM Evolution (GSM / EDGE), Worldwide Interoperability for Microwave Access (WiMax), or Ultra Mobile Broadband (UMB), just to mention a few possible implementations.

[0046] In the communication network 1 , wireless devices e.g. a user equipment (UE) 10 such as a mobile station, a non-access point (non-AP) STA, a STA, a wireless device and / or a wireless terminal, communicate via one or more AN, e.g. a RAN, to one or more CNs. It should be understood by those skilled in the art that “UE” is a non-limiting term which means any terminal, wireless communication terminal, internet of things (loT) capable device, Machine Type Communication (MTC) device, Device to Device (D2D) terminal, or node e.g. smart phone, laptop, mobile phone, sensor, relay, mobile tablets or even a base station communicating within a cell.

[0047] The communication network 1 comprises a radio network node 12 providing radio coverage over a geographical area, e.g. a first service area, of a first radio access technology (RAT), such as NR, LTE, UMTS, Wi-Fi or similar. The radio network node 12 may be a radio access network node such as radio network controller or an access point such as a wireless local area network (WLAN) access point or an Access Point Station (AP STA), an access controller, a base station, e.g. a radio base station such as a NodeB, an evolved Node B (eNB, eNodeB), a base transceiver station, Access Point Base Station, base station router, a transmission arrangement of a radio base station, a standalone access point or any other network unit capable of serving a UE within the service area served by the radio network node 12 depending e.g. on the first radio access technology and terminology used.

[0048] The communication network 1 may further comprise a number of network nodes providing network functions (NF) or actually instantiations of NFs also referred to as NF instances. The communication network 1 comprises a server 13, for example, an online certificate validation protocol (OCVP) server, and a second network node 14 such as authentication server e.g., a PKI server comprising one or more PKI entities, also referred to as PKI end entities. The respective node may be a standalone server, a cloud-implemented server, a distributed server or processing resources in a server farm or same node. Embodiments herein may be implemented as physical bare metal, virtual or cloud native such as Kubernetes environment in, e.g., hyper-cloud networks.

[0049] According to embodiments herein a client 110 is arranged to provide a solution for efficient certificate validation. This client may be installed on the UE 10, a sever, a radio network node or similar.

[0050] The client 110 transmits a validation request to the server 13, wherein the validation request comprises: a client identity allowing the server to identify a PKI entity associated to the client, an indication of a certificate to be validated, and a client authentication data such as signature, client certificate or similar, for allowing the server to validate the validation request. The server 13 checks whether the certificate is from a trusted domain and has been revoked or not. The server 13 then transmits a response to the client 110, wherein the response indicates validation or rejection of the validation request.

[0051] Embodiments herein may simplify operation and maintenance activities in a secure network based on, for example, TLS and standard X.509 PKI system. Furthermore, embodiments herein may also improve security by avoiding unexpected entity configuration that breaches a zero trust condition. That is, that no one can add further unexpected trusted certificates in the entity, bypassing the trust domain segregation and zero trust compliance.

[0052] Fig. 2 is a combined flowchart and signalling scheme according to some alternative embodiments herein. The order of the actions may be performed in any suitable manner.

[0053] Action 201. The client 110 may receive a communication request or a message comprising a certificate for authenticating an associated user or UE, such as a node or a subscriber.

[0054] Action 202. The client 110 may add input parameters to a validation request, such input parameters may comprise a client identity allowing the server to identify a PKI entity associated to the client, an indication of the certificate to be validated, such as certificate ID, and a client authentication data such as signature, client certificate or similar.

[0055] Action 203. The client 110 transmits the validation request to the server 13.

[0056] Action 204. The server 13 may identify the PKI entity, such as PKI end entity, of the client 110. Action 205. The server 13 checks that a domain of the certificate is in a trusted domains list of the PKI entity associated to the client 110.

[0057] Action 206. The server 13 further checks whether the certificate has been revoked or not in a certificate revocation list.

[0058] Action 207. The server 13 further transmits a response to the client 110. The response indicates validation or rejection of the validation request.

[0059] Embodiments herein allow a centralized certificate validation simplifying the operational and maintenance activities on the network, avoiding manual trusted certificates distribution on each single network device.

[0060] Thus, embodiments herein may increase the overall security level in a complex network avoiding cases where some network devices can be configured with weaker PKI security constraints, for example, CRL check disabled, or with some additional trusted certificates accidentally or maliciously added, bypassing the trust domain segregation and zero trust compliance.

[0061] Example embodiments of the method performed by the client 110 for handling communication in the communication network 1 will now be described with reference to a flowchart depicted in Fig. 3. The actions do not have to be taken in the order stated below, but may be taken in any suitable order. Optional actions are marked with dashed boxes.

[0062] Action 301. The client 110 may obtain the certificate to be validated from a user / application / server.

[0063] Action 302. The client 110 may check a caching function for identifying whether the validation request has been validated or rejected before.

[0064] Action 303. The client 110 transmits the validation request to the server 13, wherein the validation request comprises: a client identity allowing the server 13 to identify a PKI entity associated to the client 110, an indication of a certificate to be validated, and a client authentication data such as signature, client certificate or similar, for allowing the server 13 to validate the validation request.

[0065] Action 304. The client 110 receives the response from the server 13, wherein the response indicates validation or rejection of the validation request.

[0066] Action 305. The client 110 may cache an indication of the response in connection with the certificate with a configurable aging time. The method may be integrated in existing TLS and / or IKE protocol. For example, the integration of an OCVP protocol in TLS / IKE suites may comprise in their implementation:

[0067] • a new configuration parameter to enable / disable OCVP protocol

[0068] • in case it is enabled, the configuration parameters to establish secure connection with OCVP Server

[0069] • in case it is enabled:

[0070] • to demand the validation of peer’s certificate to the OCVP server instead to perform it from local storage

[0071] • to skip every CRL check even if enabled because it is already included in the OCVP protocol

[0072] Example embodiments of a method performed by the server 13 for handling communication in the communication network 1 will now be described with reference to a flowchart depicted in Fig. 4. The actions do not have to be taken in the order stated below, but may be taken in any suitable order. Optional actions are marked with dashed boxes.

[0073] Action 401. The server 13 receives the validation request from the client 110, wherein the validation request comprises: the client identity allowing the server 13 to identify a PKI entity associated to the client 110, the indication of the certificate to be validated, and the client authentication data, for allowing the server 13 to validate the validation request.

[0074] Action 402. The server 13 checks that a domain of the certificate is in a trusted domains list of the PKI entity associated to the client 110.

[0075] Action 403. The server 13 further checks whether the certificate has been revoked or not in a certificate revocation list.

[0076] Action 404. The server 13 may add a timestamp to the response indicating time of validation.

[0077] Action 405. The server 13 responds with the response indicating validation or rejection of the validation request based the previous checks. The response may further comprise one or more of the following: the client identity, the indication of the certificate to be validated, and / or the client authentication data.

[0078] The method may be integrated in existing TLS and / or IKE Protocol. The new protocol may be referred to as “Online Certificate Validation Protocol” (OCVP) and may comprise a message set between an OCVP Client and an OCVP Server.

[0079] As an example, when a X.509 certificate received from a generic peer must be validated, the OCVP client issues a request to an OCVP Server and suspends the acceptance of the certificate in question until the OCVP Server provides a response.

[0080] So, the OCVP protocol can be integrated in existing authentication protocols like TLS and IKE.

[0081] Fig. 5 shows a schematic overview depicting an example of embodiments herein.

[0082] The client 110, exemplified as an OCVP client 110’ (node A), comprises some OCVP - Client settings such as OCVP Server URI: http:<uri-ocv-server; OCVP Client Name: Node-A PKI EE; OCVP Client X 509 Certificate; Truststore: - Root-CV-Server-CA; and / or Cache Enabled.

[0083] OCVP Client application programming interfaces (API) may comprise one or more of the following actions: Validate X.509 Cert, Enable / Disable Cache, Cache-cleanup.

[0084] OCVP Client Dynamic Data may comprise one or more of the following: Cache data: {[SHA-256-Peer Cert, Validity (true / false), Date&Time] ... }

[0085] The server 13 such as an OCVP server 13’ may comprise OCVP - Server settings that may comprise one or more of the following: OCVP Server X.509 Cert (issuer: Root- CV-Server-CA); PKI URIs (optional assuming OCV Server is not integrated in the PKI System but it collaborates with external PKI systems).

[0086] OCVP Server APIs may comprise the following action: Validate X.509 Cert.

[0087] The PKI server 14’ may comprise one or more PKI entities, such as certificate validation (CV) server PKI EE, a Node-A PKI EE, a Node-B PKI EE. The PKI server may also be configured with a certificate authorities comprising one or more CRL. A PKI system may be represented by a set of multiple PKI systems with which the OCVP Server 13’, using available interface such as northbound interface (NBI) or similar, can collect data to perform the Certificate Validation, including PKI End Entity, Trusted profiles or Certificates, Certificate Revocation List.

[0088] Thus, the OCVP client 110’ may transmit an HTTP Certificate Validation Request to the OCVP server 13’. The OCVP server 13’ transmits Get PKI EE, GET trust profile and get CRL. Thus, the OCVP server 13’ check domain and revocation of the certificate and responds back to the OCVP client 110’ with an HTTP Certificate Validation Response. Fig. 6 discloses an example of the method herein in a schematic manner. Action 1. The OCVP client 110’ obtains a X.509 certificate to be validated, such as received in a handshake message. Action 2. The OCVP client 110’ checks if the certificate to be validated is cached in the cache of the OCVP client 110’. That not being the case, the OCVP client 110’ sends to OCVP server 13’ a certificate validation request. Hence, the OCVP client 110’ checks the cache, and if not cached sends the X.509 certificate to be validated. Action 3. The validation request such as the HTTP Certificate Validation Request is sent and comprises: input parameters such as OCVP Client Name; OCVP Client X.509 Cert; X.509 Cert to be validated; and / or Signature. Action 4.1. Validation Request is checked, wherein the server identifies the PKI EE associated to the OCVP Client 110’ and its Trust Profile (trust domain list). Action 4.2. The OCVP server 13’ further checks to verify whether the X.509 cert, from the issuer, to be validated is in a Certificate Revocation List or not. Action 5. The OCVP server 13’ sends a response to the OCVP client 110’. Action 6. The OCVP client 110’ may update its cache such as add OCVP Client Dynamic Data: Cache: {[SHA-256- Peer Cert, Validity (true / false), Date&Time] ... } to cache. For example, the OCVP Client 110’ on Node A, may process the response from OCVP Server 13’. In case of success: It can optionally store the received trusted CAs and CRLs into its cache to be used in next handshake, and / or proceed with other TLS Handshake steps. Action 7. The OCVP client 110’ may thus provide or obtain the result of X.509 Cert Validation.

[0089] Fig. 7 is a schematic signalling scheme depicting an example of Online Certificate Validation Protocol integrated in TLS Handshake. The client 110 is exemplified as being part of the TLS client 110”, and the server 13 is exemplified as an OCVP responder 13”. The suggested OCVP protocol may be deployed in standalone mode but its common use is the integration in the well-known security suite like TLS as shown in Fig. 7.

[0090] Action 1. The TLS client 110” transmits a Client Hello to a TLS server.

[0091] Action 2. The TLS server responds with a Sever Hello. Action 3. The TLS server further transmits a server certificate to the TLS client. Action 4. Furthermore, the TLS server may initiate a Server Key exchange with the TLS client 110”.

[0092] Action 5. The TLS client 110” transmits an OCVP request indicating a request type such as a validation. The certificate is identified with a certID. The OCVP responder 13” may check chain of certificate ID in the request and is validated by the OCVP responder 13”. Action 6. The OCVP responder 13” may respond with OCVP response indicating validation status. HTTP may be the transport protocol used. Action 7. The TLS client 110” may then cache the response. This may be done to maintain load at a reasonable level. Action 8. The TLS client 110” may perform a local trust validation. Action 9. The TLS client 110” may continue and transmit client key exchange to the TLS server. Action 10. The TLS server may respond with a Server Hello done message. Action 11. The TLS client 110” may transmit a Client Hello done message to the TLS server.

[0093] Examples of the validation request and the response as OCVP Protocol Messages:

[0094] The OCVP protocol may specify the messages and the data to be exchanged between OCVP client and server.

[0095] Two messages are defined:

[0096] • OCVP Request Message sent by OCVP Client 110’ to OCVP Server 13’

[0097] • OCVP Response Message sent by OCVP Server 13’ to OCVP Client 110’

[0098] OCVP Request Message

[0099] The message is defined by the following ASN.1 syntax: OCVPRequest ::= SEQUENCE { sRequest sRequestDTO, sSignature sSignatureDTO } sRequestDTO ::= SEQUENCE { version [0] EXPLICIT Version DEFAULT v1 , ocvpCIientName [1] EXPLICIT GeneralName, requestitems SEQUENCE OF Requestitem DTO

[0100] } Requestitem DTO ::= SEQUENCE { requestTrustCert Certificate, requestType ENUMERATED { validate (0), -- Trust Chain Validation others (1) -- For future extension } } OCVP Response Message

[0101] The message is defined by the following ASN.1 syntax: OCVPResponse ::= SEQUENCE { responsestatus sResponseStatus, sResponse sResponseDTO, sSignature sSignatureDTO

[0102] } sResponseStatus ::= ENUMERATED { successful (0), -- Response has valid confirmations. malformedRequest (1), -- Illegal request internalError (2), -- Internal error in OCVP Server try Later (3), -- Try again later. unauthorized (4) -- Request unauthorized sResponseDTO ::= SEQUENCE { version [0] EXPLICIT Version DEFAULT v1 , ocvpServerName [1] EXPLICIT GeneralName, responseAt [2] GeneralizedTime, responseList SEQUENCE OF singleResponseltem

[0103] } singleResponseltem ::= SEQUENCE { validateAt [1] GeneralizedTime, requestTrustCert Certificate, singleResponse sSingleResponseDTO

[0104] } sSingleResponseDTO ::= SEQUENCE { requestType ENUMERATED { validated (0), -- Check Trust chain validation, others (1) -- For future extension }, validationstatus ENUMERATED { valid (0) -- Trust chain valid, notvalid (1) -- Trust chain not valid, unknow (2) -- Unknown Validation Status } }

[0105] Global Data Types

[0106] Global Structures are defined by the following ASN.1 Syntax: sSignatureDTO ::= SEQUENCE { signatureAlgorithm Algorithmidentifier, signature BIT STRING, ocvpCert Certificate - OCVP Client / Server Certificate

[0107] }

[0108] Version ::= INTEGER { v1(0) }

[0109] The response generated by the server 13 may comprise the timestamp when it is generated; moreover, any response item returns the time when the validation is checked.

[0110] For this service to be effective a connection to the server 13 shall be available, if not, a fallback procedure may be implemented.

[0111] A denial-of-service vulnerability is evident with respect to a flood of queries.

[0112] Replay attack may be mitigated by using trust chain validation both on the client 110 and the server 13.

[0113] Fig. 8 shows a block diagram depicting the client 110 for handling communication in the communication network.

[0114] The client 110 may comprise processing circuitry 801 , e.g. one or more processors, configured to perform the methods herein.

[0115] The client 110 and / or the processing circuitry 801 is configured to transmit the validation request to the server 13, wherein the validation request comprises: the client identity allowing the server 13 to identify the PKI entity associated to the client 110, the indication of the certificate to be validated, and the client authentication data, for allowing the server 13 to validate the validation request.

[0116] The client 110 and / or the processing circuitry 801 is configured to receive the response from the server 13, wherein the response indicates validation or rejection of the validation request.

[0117] The client 110 and / or the processing circuitry 801 may be configured to check the caching function for identifying whether the validation request has been validated or rejected before.

[0118] The client 110 and / or the processing circuitry 801 may be configured to obtain the certificate to be validated from a user / application / server. The client 110 and / or the processing circuitry 801 may be configured to cache the indication of the response in connection with the certificate with a configurable aging time.

[0119] The method may be integrated in existing Transport Layer Security and / or Internet Key Exchange Protocol.

[0120] According to examples herein, the client 110 and / or the processing circuitry 801 may be configured to enable Online Certificate Validation Protocol, providing an uniform resource identifier (URI) of the Online Certificate Validation Server.

[0121] The client 110 and / or the processing circuitry 801 may be provisioned with the Trusted Certificates required to authenticate the Server response only.

[0122] The client 110 and / or the processing circuitry 801 may be configured to cache the Server’s responses with a configurable aging time, to minimize the network overhead.

[0123] When peer certificate validation is required, the client 110 and / or the processing circuitry 801 may be configured to: in case the cache is enabled, check if the peer certificate is already into its cache acting according to the certificate validation status reported here; otherwise, if cache is disabled or if entry is not present in the cache, send the

[0124] Online Certificate Validation Request to the Server specifying:

[0125] - the “Requestor Name” allowing the Server to identify the PKI End Entity associated to the Client,

[0126] - the peer X.509 certificate to be validated,

[0127] - the signature, the signature algorithm and Client public Key X.509 Certificate, allowing the server to perform authentication and integrity checks on the request, process the response, updating the cache if enabled, with: hash value of peer X.509 certificate,

[0128] - validity (true or false), date and / or time in Coordinated Universal Time (UTC) format, in case cache is enabled, the client 110 and / or the processing circuitry 801 may be configured to:

[0129] - flush the cache on demand, remove from cache the data after the configured ageing time.

[0130] The client 110 further comprises a memory 805. The memory comprises one or more units to be used to store data on, such as indications, certificates, security information, indications, reconfiguration, applications to perform the methods disclosed herein when being executed, and similar. The client 110 comprises a communication interface 806 comprising transmitter, receiver, transceiver and / or one or more antennas. Thus, it is herein provided the client 110 for handling communication in a wireless communications network, wherein the client 110 comprises processing circuitry and a memory, said memory comprising instructions executable by said processing circuitry whereby said client 110 is operative to perform any of the methods herein.

[0131] The methods according to the embodiments described herein for the client 110 are respectively implemented by means of e.g. a computer program product 807 or a computer program product, comprising instructions, i.e., software code portions, which, when executed on at least one processor, cause the at least one processor to carry out the actions described herein, as performed by the client 110. The computer program product 807 may be stored on a computer-readable storage medium 808, e g. a universal serial bus (USB) stick, a disc or similar. The computer-readable storage medium 808, having stored thereon the computer program product, may comprise the instructions which, when executed on at least one processor, cause the at least one processor to carry out the actions described herein, as performed by the client 110. In some embodiments, the computer-readable storage medium may be a non-transitory or transitory computer-readable storage medium.

[0132] Fig. 9 shows a block diagram depicting the server 13 for handling communication in the communication network.

[0133] The server 13 may comprise processing circuitry 901 , e.g. one or more processors, configured to perform the methods herein.

[0134] The server 13 and / or the processing circuitry 901 is configured to receive the validation request from the client 110, wherein the validation request comprises: the client identity allowing the server 13 to identify the PKI entity associated to the client 110, the indication of the certificate to be validated, and the client authentication data, for allowing the server 13 to validate the validation request.

[0135] The server 13 and / or the processing circuitry 901 is configured to check that the domain of the certificate is in the trusted domains list of the PKI entity associated to the client; and to check whether the certificate has been revoked or not in the certificate revocation list.

[0136] The server 13 and / or the processing circuitry 901 is configured to respond with the response indicating validation or rejection of the validation request based the previous checks. The server 13 and / or the processing circuitry 901 may be configured to add the timestamp to the response indicating time of validation.

[0137] The response may further comprise one or more of the following: the client identity, the indication of the certificate to be validated, and / or the client authentication data.

[0138] The method may be integrated in existing Transport Layer Security and / or Internet Key Exchange Protocol.

[0139] Thus, according to some examples herein the server 13 may be integrated in an existent PKI system, or the server 13 may collaborate with one or more PKI Systems to know for each single PKI End Entity the list of required Trusted Certificate Authorities (CA) and the Certificate Revocation Lists (CRL).

[0140] The server 13 and / or the processing circuitry 901 may be configured to process the validation request performing one or more of the following verifications:

[0141] - validating the client signature, returning an error in case of failure; identifying the PKI End Entity associated to the Client from the provided Requestor Name in the request message. In case PKI End Entity (EE) has not been found, the Server shall reply to the client with a generic error,

[0142] - verifying the validity of peer certificate returning a proper status (“valid” / ”not valid”) to the Client by validating provided peer X.509 certificate against the Trusted CAs defined for the Client PKI EE, and verifying that peer X.509 certificate has not been revoked.

[0143] The server 13 and / or the processing circuitry 901 may be configured to, in the response to the client 110, provide signature, signature algorithm and its X.509 certificate, allowing the client 110 to verify the integrity and authentication of the response.

[0144] The server 13 further comprises a memory 905. The memory comprises one or more units to be used to store data on, such as indications, certificates, validation information, indications, reconfiguration, applications to perform the methods disclosed herein when being executed, and similar. The server 13 comprises a communication interface 906 comprising transmitter, receiver, transceiver and / or one or more antennas. Thus, it is herein provided the server 13 for handling communication in a communication network, wherein the server 13 comprises processing circuitry and a memory, said memory comprising instructions executable by said processing circuitry whereby said server 13 is operative to perform any of the methods herein.

[0145] The methods according to the embodiments described herein for the server 13 are respectively implemented by means of e.g. a computer program product 907 or a computer program product, comprising instructions, i.e., software code portions, which, when executed on at least one processor, cause the at least one processor to carry out the actions described herein, as performed by the server 13. The computer program product 907 may be stored on a computer-readable storage medium 908, e g. a USB stick, a disc or similar. The computer-readable storage medium 908, having stored thereon the computer program product, may comprise the instructions which, when executed on at least one processor, cause the at least one processor to carry out the actions described herein, as performed by the server 13. In some embodiments, the computer-readable storage medium may be a non-transitory or transitory computer- readable storage medium.

[0146] As will be readily understood by those familiar with communications design, that functions means or modules may be implemented using digital logic and / or one or more microcontrollers, microprocessors, or other digital hardware. In some embodiments, several or all of the various functions may be implemented together, such as in a single application-specific integrated circuit (ASIC), or in two or more separate devices with appropriate hardware and / or software interfaces between them. Several of the functions may be implemented on a processor shared with other functional components of a radio network node, for example.

[0147] Alternatively, several of the functional elements of the processing means discussed may be provided through the use of dedicated hardware, while others are provided with hardware for executing software, in association with the appropriate software or firmware. Thus, the term “processor” or “controller” as used herein does not exclusively refer to hardware capable of executing software and may implicitly include, without limitation, digital signal processor (DSP) hardware, read-only memory (ROM) for storing software, random-access memory for storing software and / or program or application data, and non-volatile memory. Other hardware, conventional and / or custom, may also be included. Designers of communications receivers will appreciate the cost, performance, and maintenance trade-offs inherent in these design choices.

[0148] Fig. 10 shows an example of a communication system QQ100 in accordance with some embodiments.

[0149] In the example, the communication system QQ100 includes a telecommunication network QQ102 that includes an access network QQ104, such as a radio access network (RAN), and a core network QQ106, which includes one or more core network nodes QQ108. The access network QQ104 includes one or more access network nodes, such as network nodes QQ110a and QQ110b (one or more of which may be generally referred to as network nodes QQ110) being examples of the first radio network node 12 and second radio network node 13, or any other similar 3rdGeneration Partnership Project (3GPP) access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node, being examples of the entities herein, is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor. Thus, it will be understood that network nodes include disaggregated implementations or portions thereof. For example, in some embodiments, the telecommunication network QQ102 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in the telecommunication network QQ102 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in the telecommunication network QQ102, including one or more network nodes QQ110 and / or core network nodes QQ108.

[0150] Examples of an ORAN network node include an open radio unit (0-Rll), an open distributed unit (0-Dll), an open central unit (O-CU), including an O-CU control plane (O-CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near- real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an A1 , F1 , W1, E1, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an 0-2 interface defined by the O-RAN Alliance or comparable technologies. The network nodes QQ110 facilitate direct or indirect connection of the user equipment (UE) 10, such as by connecting UEs QQ112a, QQ112b, QQ112c, and QQ112d (one or more of which may be generally referred to as UEs QQ112) to the core network QQ106 over one or more wireless connections.

[0151] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, the communication system QQ100 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. The communication system QQ100 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0152] The UEs QQ112 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with the network nodes QQ110 and other communication devices. Similarly, the network nodes QQ110 are arranged, capable, configured, and / or operable to communicate directly or indirectly with the UEs QQ112 and / or with other network nodes or equipment in the telecommunication network QQ102 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in the telecommunication network QQ102.

[0153] In the depicted example, the core network QQ106 connects the network nodes QQ110 to one or more hosts, such as host QQ116. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. The core network QQ106 includes one more core network nodes (e.g., core network node QQ108) such as network node 15 that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are generally applicable to the corresponding components of the core network node QQ108. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).

[0154] The host QQ116 may be under the ownership or control of a service provider other than an operator or provider of the access network QQ104 and / or the telecommunication network QQ102, and may be operated by the service provider or on behalf of the service provider. The host QQ116 may host a variety of applications to provide one or more service. Examples of such applications include live and prerecorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0155] As a whole, the communication system QQ100 of Fig. 10 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0156] In some examples, the telecommunication network QQ102 is a cellular network that implements 3GPP standardized features. Accordingly, the telecommunications network QQ102 may support network slicing to provide different logical networks to different devices that are connected to the telecommunication network QQ102. For example, the telecommunications network QQ102 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0157] In some examples, the UEs QQ112 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to the access network QQ104 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the access network QQ104. Additionally, a UE may be configured for operating in single- or multi- RAT or multi-standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e. being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC). In the example, the hub QQ114 communicates with the access network QQ104 to facilitate indirect communication between one or more UEs (e.g., UE QQ112c and / or QQ112d) and network nodes (e.g., network node QQ110b). In some examples, the hub QQ114 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, the hub QQ114 may be a broadband router enabling access to the core network QQ106 for the UEs. As another example, the hub QQ114 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes QQ110, or by executable code, script, process, or other instructions in the hub QQ114. As another example, the hub QQ114 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, the hub QQ114 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, the hub QQ114 may retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, which the hub QQ114 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, the hub QQ114 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0158] The hub QQ114 may have a constant / persistent or intermittent connection to the network node QQ110b. The hub QQ114 may also allow for a different communication scheme and / or schedule between the hub QQ114 and UEs (e.g., UE QQ112c and / or QQ112d), and between the hub QQ114 and the core network QQ106. In other examples, the hub QQ114 is connected to the core network QQ106 and / or one or more UEs via a wired connection. Moreover, the hub QQ114 may be configured to connect to an M2M service provider over the access network QQ104 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with the network nodes QQ110 while still connected via the hub QQ114 via a wired or wireless connection. In some embodiments, the hub QQ114 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to the network node QQ110b. In other embodiments, the hub QQ114 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node QQ110b, but which is additionally capable of operating as a communication start and / or end point for certain data channels. Figure 11 shows a UE QQ200 in accordance with some embodiments. As used herein, a UE refers to a device capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other UEs. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by the 3rd Generation Partnership Project (3GPP), including narrow band internet of things (NB-loT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0159] A UE may support device-to-device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who owns and / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0160] The UE QQ200 includes processing circuitry QQ202 that is operatively coupled via a bus QQ204 to an input / output interface QQ206, a power source QQ208, a memory QQ210, a communication interface QQ212, and / or any other component, or any combination thereof. Certain UEs may utilize all or a subset of the components shown in Figure 11. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0161] The processing circuitry QQ202 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in the memory QQ210. The processing circuitry QQ202 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, the processing circuitry QQ202 may include multiple central processing units (CPUs).

[0162] In the example, the input / output interface QQ206 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into the UE QQ200. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.

[0163] In some embodiments, the power source QQ208 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. The power source QQ208 may further include power circuitry for delivering power from the power source QQ208 itself, and / or an external power source, to the various parts of the UE QQ200 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of the power source QQ208. Power circuitry may perform any formatting, converting, or other modification to the power from the power source QQ208 to make the power suitable for the respective components of the UE QQ200 to which power is supplied.

[0164] The memory QQ210 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, the memory QQ210 includes one or more application programs QQ214, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data QQ216. The memory QQ210 may store, for use by the UE QQ200, any of a variety of various operating systems or combinations of operating systems.

[0165] The memory QQ210 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual inline memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUlCC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ The memory QQ210 may allow the UE QQ200 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in the memory QQ210, which may be or comprise a device-readable storage medium.

[0166] The processing circuitry QQ202 may be configured to communicate with an access network or other network using the communication interface QQ212. The communication interface QQ212 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna QQ222. The communication interface QQ212 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter QQ218 and / or a receiver QQ220 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, the transmitter QQ218 and receiver QQ220 may be coupled to one or more antennas (e.g., antenna QQ222) and may share circuit components, software or firmware, or alternatively be implemented separately.

[0167] In the illustrated embodiment, communication functions of the communication interface QQ212 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0168] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface QQ212, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0169] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0170] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Nonlimiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for Augmented Reality (AR) or Virtual Reality (VR), a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to the UE QQ200 shown in Figure 11.

[0171] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3GPP NB-loT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0172] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g. by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0173] Figure 12 shows a network node QQ300 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with a UE and / or with other network nodes or equipment, in a telecommunication network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs) and NR NodeBs (gNBs)), O-RAN nodes or components of an O-RAN node (e.g., O-RU, O-DU, O-CU).

[0174] Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an O-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0175] Other examples of network nodes include multiple transmission point (multi- TRP) 5G access nodes, multi-standard radio (MSR) equipment such as MSR BSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0176] The network node QQ300 includes a processing circuitry QQ302, a memory QQ304, a communication interface QQ306, and a power source QQ308. The network node QQ300 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which the network node QQ300 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, the network node QQ300 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory QQ304 for different RATs) and some components may be reused (e.g., a same antenna QQ310 may be shared by different RATs). The network node QQ300 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node QQ300, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node QQ300.

[0177] The processing circuitry QQ302 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node QQ300 components, such as the memory QQ304, to provide network node QQ300 functionality.

[0178] In some embodiments, the processing circuitry QQ302 includes a system on a chip (SOC). In some embodiments, the processing circuitry QQ302 includes one or more of radio frequency (RF) transceiver circuitry QQ312 and baseband processing circuitry QQ314. In some embodiments, the radio frequency (RF) transceiver circuitry QQ312 and the baseband processing circuitry QQ314 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry QQ312 and baseband processing circuitry QQ314 may be on the same chip or set of chips, boards, or units.

[0179] The memory QQ304 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry QQ302. The memory QQ304 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry QQ302 and utilized by the network node QQ300. The memory QQ304 may be used to store any calculations made by the processing circuitry QQ302 and / or any data received via the communication interface QQ306. In some embodiments, the processing circuitry QQ302 and memory QQ304 is integrated.

[0180] The communication interface QQ306 is used in wired or wireless communication of signalling and / or data between a network node, access network, and / or UE. As illustrated, the communication interface QQ306 comprises port(s) / terminal(s) QQ316 to send and receive data, for example to and from a network over a wired connection. The communication interface QQ306 also includes radio frontend circuitry QQ318 that may be coupled to, or in certain embodiments a part of, the antenna QQ310. Radio front-end circuitry QQ318 comprises filters QQ320 and amplifiers QQ322. The radio front-end circuitry QQ318 may be connected to an antenna QQ310 and processing circuitry QQ302. The radio front-end circuitry may be configured to condition signals communicated between antenna QQ310 and processing circuitry QQ302. The radio front-end circuitry QQ318 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry QQ318 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters QQ320 and / or amplifiers QQ322. The radio signal may then be transmitted via the antenna QQ310. Similarly, when receiving data, the antenna QQ310 may collect radio signals which are then converted into digital data by the radio front-end circuitry QQ318. The digital data may be passed to the processing circuitry QQ302. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0181] In certain alternative embodiments, the network node QQ300 does not include separate radio front-end circuitry QQ318, instead, the processing circuitry QQ302 includes radio front-end circuitry and is connected to the antenna QQ310. Similarly, in some embodiments, all or some of the RF transceiver circuitry QQ312 is part of the communication interface QQ306. In still other embodiments, the communication interface QQ306 includes one or more ports or terminals QQ316, the radio front-end circuitry QQ318, and the RF transceiver circuitry QQ312, as part of a radio unit (not shown), and the communication interface QQ306 communicates with the baseband processing circuitry QQ314, which is part of a digital unit (not shown).

[0182] The antenna QQ310 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The antenna QQ310 may be coupled to the radio front-end circuitry QQ318 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, the antenna QQ310 is separate from the network node QQ300 and connectable to the network node QQ300 through an interface or port.

[0183] The antenna QQ310, communication interface QQ306, and / or the processing circuitry QQ302 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, the antenna QQ310, the communication interface QQ306, and / or the processing circuitry QQ302 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0184] The power source QQ308 provides power to the various components of network node QQ300 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source QQ308 may further comprise, or be coupled to, power management circuitry to supply the components of the network node QQ300 with power for performing the functionality described herein. For example, the network node QQ300 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source QQ308. As a further example, the power source QQ308 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0185] Embodiments of the network node QQ300 may include additional components beyond those shown in Figure 12 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node QQ300 may include user interface equipment to allow input of information into the network node QQ300 and to allow output of information from the network node QQ300. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node QQ300.

[0186] Figure 13 is a block diagram of a host QQ400, which may be an embodiment of the host QQ116 of Figure 10, in accordance with various aspects described herein. As used herein, the host QQ400 may be or comprise various combinations hardware and / or software, including a standalone server, a blade server, a cloud-implemented server, a distributed server, a virtual machine, container, or processing resources in a server farm. The host QQ400 may provide one or more services to one or more UEs.

[0187] The host QQ400 includes processing circuitry QQ402 that is operatively coupled via a bus QQ404 to an input / output interface QQ406, a network interface QQ408, a power source QQ410, and a memory QQ412. Other components may be included in other embodiments. Features of these components may be substantially similar to those described with respect to the devices of previous figures, such as Figures 11 and 12, such that the descriptions thereof are generally applicable to the corresponding components of host QQ400.

[0188] The memory QQ412 may include one or more computer programs including one or more host application programs QQ414 and data QQ416, which may include user data, e.g., data generated by a UE for the host QQ400 or data generated by the host QQ400 for a UE. Embodiments of the host QQ400 may utilize only a subset or all of the components shown. The host application programs QQ414 may be implemented in a container-based architecture and may provide support for video codecs (e.g., Versatile Video Coding (WC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAG, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for multiple different classes, types, or implementations of UEs (e.g., handsets, desktop computers, wearable display systems, heads-up display systems). The host application programs QQ414 may also provide for user authentication and licensing checks and may periodically report health, routes, and content availability to a central node, such as a device in or on the edge of a core network. Accordingly, the host QQ400 may select and / or indicate a different host for over-the-top services for a UE. The host application programs QQ414 may support various protocols, such as the HTTP Live Streaming (HLS) protocol, Real-Time Messaging Protocol (RTMP), Real-Time Streaming Protocol (RTSP), Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc.

[0189] Figure 14 is a block diagram illustrating a virtualization environment QQ500 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments QQ500 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment QQ500 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an 0-2 interface.

[0190] Applications QQ502 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment Q400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.

[0191] Hardware QQ504 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers QQ506 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs QQ508a and QQ508b (one or more of which may be generally referred to as VMs QQ508), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer QQ506 may present a virtual operating platform that appears like networking hardware to the VMs QQ508.

[0192] The VMs QQ508 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer QQ506. Different embodiments of the instance of a virtual appliance QQ502 may be implemented on one or more of VMs QQ508, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0193] In the context of NFV, a VM QQ508 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, nonvirtualized machine. Each of the VMs QQ508, and that part of hardware QQ504 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs QQ508 on top of the hardware QQ504 and corresponds to the application QQ502.

[0194] Hardware QQ504 may be implemented in a standalone network node with generic or specific components. Hardware QQ504 may implement some functions via virtualization. Alternatively, hardware QQ504 may be part of a larger cluster of hardware (e.g. such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration QQ510, which, among others, oversees lifecycle management of applications QQ502. In some embodiments, hardware QQ504 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signalling can be provided with the use of a control system QQ512 which may alternatively be used for communication between hardware nodes and radio units.

[0195] Figure 15 shows a communication diagram of a host QQ602 communicating via a network node QQ604 with a UE QQ606 over a partially wireless connection in accordance with some embodiments. Example implementations, in accordance with various embodiments, of the UE (such as a UE QQ112a of Figure 10 and / or UE QQ200 of Figure 11), network node (such as network node QQ110a of Figure 10 and / or network node QQ300 of Figure 12), and host (such as host QQ116 of Figure 10 and / or host QQ400 of Figure 13) discussed in the preceding paragraphs will now be described with reference to Figure 15.

[0196] Like host QQ400, embodiments of host QQ602 include hardware, such as a communication interface, processing circuitry, and memory. The host QQ602 also includes software, which is stored in or accessible by the host QQ602 and executable by the processing circuitry. The software includes a host application that may be operable to provide a service to a remote user, such as the UE QQ606 connecting via an over-the-top (OTT) connection QQ650 extending between the UE QQ606 and host QQ602. In providing the service to the remote user, a host application may provide user data which is transmitted using the OTT connection QQ650. The network node QQ604 includes hardware enabling it to communicate with the host QQ602 and UE QQ606. The connection QQ660 may be direct or pass through a core network (like core network QQ106 of Figure 10) and / or one or more other intermediate networks, such as one or more public, private, or hosted networks. For example, an intermediate network may be a backbone network or the Internet.

[0197] The UE QQ606 includes hardware and software, which is stored in or accessible by UE QQ606 and executable by the UE’s processing circuitry. The software includes a client application, such as a web browser or operator-specific “app” that may be operable to provide a service to a human or non-human user via UE QQ606 with the support of the host QQ602. In the host QQ602, an executing host application may communicate with the executing client application via the OTT connection QQ650 terminating at the UE QQ606 and host QQ602. In providing the service to the user, the UE's client application may receive request data from the host's host application and provide user data in response to the request data. The OTT connection QQ650 may transfer both the request data and the user data. The UE's client application may interact with the user to generate the user data that it provides to the host application through the OTT connection QQ650.

[0198] The OTT connection QQ650 may extend via a connection QQ660 between The host QQ602 and the network node QQ604 and via a wireless connection QQ670 between the network node QQ604 and the UE QQ606 to provide the connection between the host QQ602 and the UE QQ606. The connection QQ660 and wireless connection QQ670, over which the OTT connection QQ650 may be provided, have been drawn abstractly to illustrate the communication between the host QQ602 and the UE QQ606 via the network node QQ604, without explicit reference to any intermediary devices and the precise routing of messages via these devices.

[0199] As an example of transmitting data via the OTT connection QQ650, in step QQ608, the host QQ602 provides user data, which may be performed by executing a host application. In some embodiments, the user data is associated with a particular human user interacting with the UE QQ606. In other embodiments, the user data is associated with a UE QQ606 that shares data with the host QQ602 without explicit human interaction. In step QQ610, the host QQ602 initiates a transmission carrying the user data towards the UE QQ606. The host QQ602 may initiate the transmission responsive to a request transmitted by the UE QQ606. The request may be caused by human interaction with the UE QQ606 or by operation of the client application executing on the UE QQ606. The transmission may pass via the network node QQ604, in accordance with the teachings of the embodiments described throughout this disclosure. Accordingly, in step QQ612, the network node QQ604 transmits to the UE QQ606 the user data that was carried in the transmission that the host QQ602 initiated, in accordance with the teachings of the embodiments described throughout this disclosure. In step QQ614, the UE QQ606 receives the user data carried in the transmission, which may be performed by a client application executed on the UE QQ606 associated with the host application executed by the host QQ602.

[0200] In some examples, the UE QQ606 executes a client application which provides user data to the host QQ602. The user data may be provided in reaction or response to the data received from the host QQ602. Accordingly, in step QQ616, the UE QQ606 may provide user data, which may be performed by executing the client application. In providing the user data, the client application may further consider user input received from the user via an input / output interface of the UE QQ606. Regardless of the specific manner in which the user data was provided, the UE QQ606 initiates, in step QQ618, transmission of the user data towards the host QQ602 via the network node QQ604. In step QQ620, in accordance with the teachings of the embodiments described throughout this disclosure, the network node QQ604 receives user data from the UE QQ606 and initiates transmission of the received user data towards the host QQ602. In step QQ622, the host QQ602 receives the user data carried in the transmission initiated by the UE QQ606.

[0201] One or more of the various embodiments improve the performance of OTT services provided to the UE QQ606 using the OTT connection QQ650, in which the wireless connection QQ670 forms the last segment. More precisely, the teachings of these embodiments may improve handling security in an efficient manner thereby provide benefits such as reduced user waiting time, better responsiveness in a secure manner, and / or extended battery lifetime.

[0202] In an example scenario, factory status information may be collected and analyzed by the host QQ602. As another example, the host QQ602 may process audio and video data which may have been retrieved from a UE for use in creating maps. As another example, the host QQ602 may collect and analyze real-time data to assist in controlling vehicle congestion (e.g., controlling traffic lights). As another example, the host QQ602 may store surveillance video uploaded by a UE. As another example, the host QQ602 may store or control access to media content such as video, audio, VR or AR which it can broadcast, multicast or unicast to UEs. As other examples, the host QQ602 may be used for energy pricing, remote control of non-time critical electrical load to balance power generation needs, location services, presentation services (such as compiling diagrams etc. from data collected from remote devices), or any other function of collecting, retrieving, storing, analyzing and / or transmitting data.

[0203] In some examples, a measurement procedure may be provided for the purpose of monitoring data rate, latency and other factors on which the one or more embodiments improve. There may further be an optional network functionality for reconfiguring the OTT connection QQ650 between the host QQ602 and UE QQ606, in response to variations in the measurement results. The measurement procedure and / or the network functionality for reconfiguring the OTT connection may be implemented in software and hardware of the host QQ602 and / or UE QQ606. In some embodiments, sensors (not shown) may be deployed in or in association with other devices through which the OTT connection QQ650 passes; the sensors may participate in the measurement procedure by supplying values of the monitored quantities exemplified above, or supplying values of other physical quantities from which software may compute or estimate the monitored quantities. The reconfiguring of the OTT connection QQ650 may include message format, retransmission settings, preferred routing etc.; the reconfiguring need not directly alter the operation of the network node QQ604. Such procedures and functionalities may be known and practiced in the art. In certain embodiments, measurements may involve proprietary UE signalling that facilitates measurements of throughput, propagation times, latency and the like, by the host QQ602. The measurements may be implemented in that software causes messages to be transmitted, in particular empty or ‘dummy’ messages, using the OTT connection QQ650 while monitoring propagation times, errors, etc.

[0204] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions and methods disclosed herein. Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communication interface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0205] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non- transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0206] It will be appreciated that the foregoing description and the accompanying drawings represent non-limiting examples of the methods and apparatus taught herein. As such, the apparatus and techniques taught herein are not limited by the foregoing description and accompanying drawings. Instead, the embodiments herein are limited only by the following claims and their legal equivalents.

[0207] References

[0208] 1. RFC 2560 - X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP

[0209] 2. RFC 2459 - Internet X.509 Public Key Infrastructure Certificate and CRL Profile

[0210] 3. RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate

[0211] Revocation List (CRL) Profile

[0212] 4. RFC 5246 - The Transport Layer Security (TLS) Protocol Version 1.2

[0213] 5. RFC 8446 - The Transport Layer Security (TLS) Protocol Version 1.3

[0214] 6. RFC 6066 - Transport Layer Security (TLS) Extensions: Extension Definitions 7. RFC 5996 - Internet Key Exchange Protocol Version 2 (IKEv2)

Claims

CLAIMS1. A method performed by a client (110) for handling communication in a communication network, the method comprising:- transmitting (303) a validation request to a server (13), wherein the validation request comprises: a client identity allowing the server (13) to identify a Public Key Infrastructure, PKI, entity associated to the client (110), an indication of a certificate to be validated, and a client authentication data, for allowing the server (13) to validate the validation request; and receiving (304) a response from the server (13), wherein the response indicates validation or rejection of the validation request.

2. The method according to claim 1, further comprising checking (302) a caching function for identifying whether the validation request has been validated or rejected before.

3. The method according to any of the claims 1-2, further comprising obtaining (301) the certificate to be validated from a user / application / server.

4. The method according to any of the claims 1-3, further comprising caching (305) an indication of the response in connection with the certificate with a configurable aging time.

5. The method according to any of the claims 1-4, wherein the method is integrated in existing Transport Layer Security and / or Internet Key Exchange Protocol.

6. A method performed by a server (13) for handling communication in a communication network, the method comprising receiving (401) a validation request from a client (110), wherein the validation request comprises: a client identity allowing the server (13) to identify a Public Key Infrastructure, PKI, entity associated to the client (110), an indication of a certificate to be validated, and a client authentication data, for allowing the server (13) to validate the validation request; checking (402) that a domain of the certificate is in a trusted domains list of the PKI entity associated to the client (110);checking (403) whether the certificate has been revoked or not in a certificate revocation list; and responding (405) with a response indicating validation or rejection of the validation request based the previous checks.

7. The method according to claim 6, further comprising adding (404) a timestamp to the response indicating time of validation.

8. The method according to any of the claims 6-7, wherein the response further comprises one or more of the following: the client identity, the indication of the certificate to be validated, and / or the client authentication data.

9. The method according to any of the claims 6-8, wherein the method is integrated in existing Transport Layer Security and / or Internet Key Exchange Protocol.

10. A computer program comprising instructions, which, when executed on at least one processor, cause the at least one processor to carry out the method according to any of the claims 1-9, as performed by the client and server, respectively.

11. A computer-readable storage medium, having stored thereon a computer program comprising instructions which, when executed on at least one processor, cause the at least one processor to carry out the method according to any of the claims 1-9, as performed by the client and server, respectively.

12. A client (110) for handling communication in a communication network, wherein the client (110) is configured to: transmit a validation request to a server (13), wherein the validation request comprises: a client identity allowing the server (13) to identify a Public Key Infrastructure, PKI, entity associated to the client (110), an indication of a certificate to be validated, and a client authentication data, for allowing the server (13) to validate the validation request; and receive a response from the server (13), wherein the response indicates validation or rejection of the validation request.

13. The client (110) according to claim 12, wherein the client (110) is further configured to check a caching function for identifying whether the validation request has been validated or rejected before.

14. The client (110) according to any of the claims 12-13, wherein the client (110) is configured to: obtain the certificate to be validated from a user / application / server.

15. The client (110) according to any of the claims 12-14, wherein the client is configured to: cache an indication of the response in connection with the certificate with a configurable aging time.

16. The client (110) according to any of the claims 12-15, wherein the method is integrated in existing Transport Layer Security and / or Internet Key Exchange Protocol.

17. A server (13) for handling communication in a communication network, wherein the server is configured to: receive a validation request from a client (110), wherein the validation request comprises: a client identity allowing the server (13) to identify a Public Key Infrastructure, PKI, entity associated to the client, an indication of a certificate to be validated, and a client authentication data, for allowing the server (13) to validate the validation request; check that a domain of the certificate is in a trusted domains list of the PKI entity associated to the client (110); check whether the certificate has been revoked or not in a certificate revocation list; and respond with a response indicating validation or rejection of the validation request based the previous checks.

18. The server (13) according to claim 17, wherein the server (13) is configured to: add a timestamp to the response indicating time of validation.

19. The server (13) according to any of the claims 17-18, wherein the response further comprises one or more of the following: the client identity, the indication of the certificate to be validated, and / or the client authentication data.

20. The server (13) according to any of the claims 17-19, wherein the method is integrated in existing Transport Layer Security and / or Internet Key Exchange Protocol.

Citation Information

Patent Citations

  • System and method for validity verification of certificate in mobile backhaul net

    CN102026161A

  • An efficient certificate validation system and methodusing validation authority in PKI

    KR1020030021778A

  • Delegating certificate validation

    US7395428B2

  • Method and system for certification path processing

    US7444509B2

  • Method and system for OCSP service optimization by intelligent caching

    WO2011090615A1