Acme challenge methods for 5gc
A digital signature/MAC-based challenge validation using the SAN field addresses domain ownership validation issues in 5G networks, enhancing efficiency and reducing operational complexity and costs in 5G core networks.
Patent Information
- Application Number
- PCT/EP2025/053066
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-27
- Filing Date
- 2025-02-06
- Publication Date
- 2025-09-04
AI Technical Summary
Existing ACME challenge methods for validating domain ownership in 5G networks face limitations such as firewall restrictions, DNS provider limitations, and server compatibility issues, leading to operational inefficiencies and increased costs in 5G core networks.
Introduce a digital signature/MAC-based challenge validation using the Subject Alternative Name (SAN) field of the certificate request, where network functions (NFs) in the operator domain are configured with digital signatures or MACs generated using operator certificates, allowing the ACME server to validate domain ownership directly.
This method simplifies domain ownership validation, reducing operational complexity and costs by eliminating the need for additional servers and ensuring secure, efficient issuance of TLS/SSL certificates in 5G core networks.
Smart Images

Figure EP2025053066_04092025_PF_FP_ABST
Abstract
Description
ACME Challenge Methods for 5GCTECHNICAL FIELD
[0001] Examples of embodiments herein relate generally to communications protocols and, more specifically, relate to ACME challenge methods using communications protocols.BACKGROUND
[0002] The ACME (Automated Certificate Management Environment) protocol supports several challenge types to validate domain ownership during the process of obtaining SSL (secure sockets layer) / TLS (transport layer security) certificates. These challenges are used to demonstrate that the entity requesting a certificate has control over the domain for which the certificate is being requested.
[0003] While these challenges are useful, it is possible to improve on these.BRIEF SUMMARY
[0004] This section is intended to include examples and is not intended to be limiting.
[0005] In an exemplary embodiment, a method is disclosed that includes receiving, at an automated certificate management environment server from a network element in a cellular network, a certificate signing request comprising indication of a domain and a subject alternative name comprising a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with the domain present in the certificate Signing Request; performing, by the automated certificate management environment server, a validation by validating the digital signature using the retrieved certificate for the operation, administration, and maintenance and validating that one or more parameters encoded in the digital signature match with corresponding one or more parameters from the certificate Signing Request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validation.
[0006] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computerprogram is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0007] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an automated certificate management environment server from a network element in a cellular network, a certificate signing request comprising indication of a domain and a subject alternative name comprising a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with the domain present in the certificate Signing Request; performing, by the automated certificate management environment server, a validation by validating the digital signature using the retrieved certificate for the operation, administration, and maintenance and validating that one or more parameters encoded in the digital signature match with corresponding one or more parameters from the certificate Signing Request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validation.
[0008] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, at an automated certificate management environment server from a network element in a cellular network, a certificate signing request comprising indication of a domain and a subject alternative name comprising a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with the domain present in the certificate Signing Request; performing, by the automated certificate management environment server, a validation by validating the digital signature using the retrieved certificate for the operation, administration, and maintenance and validating that one or more parameters encoded in the digital signature match with corresponding one or more parameters from the certificate SigningRequest; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validation.
[0009] In another exemplary embodiment, an apparatus comprises means for performing: receiving, at an automated certificate management environment server from a network element in a cellular network, a certificate signing request comprising indication of a domain and a subject alternative name comprising a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with the domain present in the certificate Signing Request; performing, by the automated certificate management environment server, a validation by validating the digital signature using the retrieved certificate for the operation, administration, and maintenance and validating that one or more parameters encoded in the digital signature match with corresponding one or more parameters from the certificate Signing Request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validation.
[0010] In an exemplary embodiment, a method is disclosed that includes generating, by an operation, administration, and maintenance in a core network of a cellular network, a digital signature using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for a network element that is in the cellular network; and communicating, by the operation, administration, and maintenance, at least the digital signature to the network element.
[0011] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0012] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: generating, by an operation, administration, and maintenance in a core network of a cellular network, a digital signature using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for a network element that is in the cellular network; and communicating, by the operation, administration, and maintenance, at least the digital signature to the network element.
[0013] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: generating, by an operation, administration, and maintenance in a core network of a cellular network, a digital signature using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for a network element that is in the cellular network; and communicating, by the operation, administration, and maintenance, at least the digital signature to the network element.
[0014] In another exemplary embodiment, an apparatus comprises means for performing: generating, by an operation, administration, and maintenance in a core network of a cellular network, a digital signature using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for a network element that is in the cellular network; and communicating, by the operation, administration, and maintenance, at least the digital signature to the network element.
[0015] In an exemplary embodiment, a method is disclosed that includes receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for an operation, administration, and maintenance and using one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a certificate signing request comprising indication of a domain and a subject alternative name comprising the digital signature; and receiving, by the network element from the automated certificate management environment server and in response to the certificate Signing Request, a transport layer security / secure sockets layer certificate issued by the automated certificate management environment server.
[0016] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0017] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for an operation, administration, and maintenance and using one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a certificate signing request comprising indication of a domain and a subject alternative name comprising the digital signature; and receiving, by the network element from the automated certificate management environment server and in response to the certificate Signing Request, a transport layer security / secure sockets layer certificate issued by the automated certificate management environment server.
[0018] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for an operation, administration, and maintenance and using one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a certificate signing request comprising indication of a domain and a subject alternative name comprising the digital signature; and receiving, by the network element from the automated certificate management environment server and in response to the certificateSigning Request, a transport layer security / secure sockets layer certificate issued by the automated certificate management environment server.
[0019] In another exemplary embodiment, an apparatus comprises means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for an operation, administration, and maintenance and using one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a certificate signing request comprising indication of a domain and a subject alternative name comprising the digital signature; and receiving, by the network element from the automated certificate management environment server and in response to the certificate Signing Request, a transport layer security / secure sockets layer certificate issued by the automated certificate management environment server.
[0020] In an exemplary embodiment, a method is disclosed that includes receiving, at an automated certificate management environment server from a network element in a cellular network, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; validating, by the automated certificate management environment server, the digital signature using the retrieved certificate for the operation, administration, and maintenance and performing a validation of the plain identifier by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier from the first request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0021] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0022] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; validating, by the automated certificate management environment server, the digital signature using the retrieved certificate for the operation, administration, and maintenance and performing a validation of the plain identifier by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier from the first request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0023] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; retrieving, by the automated certificate management environment server, acertificate for an operation, administration, and maintenance that is associated with a domain present in the first request; validating, by the automated certificate management environment server, the digital signature using the retrieved certificate for the operation, administration, and maintenance and performing a validation of the plain identifier by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier from the first request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0024] In another exemplary embodiment, an apparatus comprises means for performing: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; validating, by the automated certificate management environment server, the digital signature using the retrieved certificate for the operation, administration, and maintenance and performing a validation of the plain identifier by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier from the first request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0025] In an exemplary embodiment, a method is disclosed that includes receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a privatekey associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0026] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0027] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0028] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus toperform at least the following: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0029] In another exemplary embodiment, an apparatus comprises means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0030] In an exemplary embodiment, a method is disclosed that includes receiving, at an automated certificate management environment server from a network element in a cellular network, a first request as part of a certificate request procedure; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; sending, by the automated certificate management environment server to the network element, a response having a challenge type of a digital signature and having an url of the automated certificate managementenvironment server; validating, by the automated certificate management environment server, a digital signature retrieved using the url and the certificate for the operation, administration, and maintenance, and performing a validation of a plain identifier, retrieved using the url and having a certain identifier type and used to identify an instance of the network element, by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier retrieved from the url; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0031] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0032] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request as part of a certificate request procedure; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; sending, by the automated certificate management environment server to the network element, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; validating, by the automated certificate management environment server, a digital signature retrieved using the url and the certificate for the operation, administration, and maintenance, and performing a validation of a plain identifier, retrieved using the url and having a certain identifier type and used to identify aninstance of the network element, by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier retrieved from the url; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0033] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request as part of a certificate request procedure; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; sending, by the automated certificate management environment server to the network element, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; validating, by the automated certificate management environment server, a digital signature retrieved using the url and the certificate for the operation, administration, and maintenance, and performing a validation of a plain identifier, retrieved using the url and having a certain identifier type and used to identify an instance of the network element, by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier retrieved from the url; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0034] In another exemplary embodiment, an apparatus comprises means for performing: receiving, at an automated certificate management environment server from anetwork element in a cellular network, a first request as part of a certificate request procedure; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; sending, by the automated certificate management environment server to the network element, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; validating, by the automated certificate management environment server, a digital signature retrieved using the url and the certificate for the operation, administration, and maintenance, and performing a validation of a plain identifier, retrieved using the url and having a certain identifier type and used to identify an instance of the network element, by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier retrieved from the url; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0035] In an exemplary embodiment, a method is disclosed that includes receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with an operation, administration, and maintenance certificate on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request as part of a certificate request procedure; receiving, by the network element and from the automated certificate management environment server, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; writing, by the network element and to the automated certificate management environment server by using the url, a plain identifier having a certain identifier type and used to identify an instance of the network element, and the digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by thenetwork element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0036] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0037] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with an operation, administration, and maintenance certificate on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request as part of a certificate request procedure; receiving, by the network element and from the automated certificate management environment server, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; writing, by the network element and to the automated certificate management environment server by using the url, a plain identifier having a certain identifier type and used to identify an instance of the network element, and the digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0038] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digitalsignature that has been determined using a private key associated with an operation, administration, and maintenance certificate on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request as part of a certificate request procedure; receiving, by the network element and from the automated certificate management environment server, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; writing, by the network element and to the automated certificate management environment server by using the url, a plain identifier having a certain identifier type and used to identify an instance of the network element, and the digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0039] In another exemplary embodiment, an apparatus comprises means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with an operation, administration, and maintenance certificate on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request as part of a certificate request procedure; receiving, by the network element and from the automated certificate management environment server, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; writing, by the network element and to the automated certificate management environment server by using the url, a plain identifier having a certain identifier type and used to identify an instance of the network element, and the digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.BRIEF DESCRIPTION OF THE DRAWINGS
[0040] The accompanying drawings use reference numerals, where the same reference numerals may be used to refer to like parts throughout, but parts having the same reference numeral can differ in operation and components. In the attached drawings:
[0041] FIG. l is a signaling diagram of one example of an approach, Approach 1 , of a challenge method that concerns digital signature / MAC based challenge validation using a SAN field of the certificate request;
[0042] FIG. 2 is a signaling diagram of one example of an approach, Approach 2, of a challenge method that concerns a new identifier type for ACME challenge validation in 5GC;
[0043] FIG. 3 is a signaling diagram of one example of an approach, Approach 3, of a challenge method that concerns a new ACME challenge type for ACME challenge validation; and
[0044] FIG. 4 is a block diagram of one possible and non-limiting exemplary system in which the exemplary embodiments may be practiced.DETAILED DESCRIPTION OF THE DRAWINGS
[0045] Abbreviations that may be found in the specification and / or the drawing figures are defined below, at the end of the detailed description section.
[0046] The word “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments. All of the embodiments described in this Detailed Description are exemplary embodiments provided to enable persons skilled in the art to make or use the examples.
[0047] When more than one drawing reference numeral, word, or acronym is used within this description withand in general as used within this description, the “ / ” may be interpreted as “or”, “and”, or “both”. As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or,” mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0048] As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0049] It is noted that capital and lowercase words or phrases are considered to be the same herein. For instance, the words Slice and slice are the same, as are the phrases Network Repository Function and network repository function.
[0050] Any flow diagram or signaling diagram (such as FIGS. 1, 2, and 3) herein is considered to be a logic flow diagram, and illustrates the operation of an exemplary method, results of execution of computer program instructions embodied on a computer readable memory, functions performed by logic implemented in hardware, and / or interconnected means for performing functions in accordance with an exemplary embodiment. Block diagrams (such as FIG. 4) also illustrate the operation of an exemplary method, results of execution of computer program instructions embodied on a computer readable memory, functions performed by logic implemented in hardware, and / or interconnected means for performing functions in accordance with an exemplary embodiment. For methods, flow diagrams, and signaling diagrams, the orders of method steps, blocks in the flow, or signaling are not critical and instead are examples.
[0051] Before proceeding with details of the examples, introduction is given to topics in certain technical areas.
[0052] As previously stated, the ACME (Automated Certificate Management Environment) protocol supports several challenge types to validate domain ownership during the process of obtaining SSL / TLS certificates. These challenges are used to demonstrate that the entity requesting a certificate has control over the domain for which the certificate is being requested.
[0053] The IETF standardized primary ACME challenge types are mentioned below.
[0054] 1. HTTP-01 Challenge:
[0055] The ACME server provides a specific token, and the client proves ownership of the domain by placing a file containing this token at a specific location on the web serverassociated with the domain. The ACME server then performs an HTTP request to retrieve the file and validate the challenge.
[0056] 2. DNS-01 Challenge:
[0057] The ACME server provides a specific token, and the client proves ownership of the domain by adding a DNS TXT record containing the token to the domain's DNS configuration. The ACME server performs a DNS query to verify the presence of the record.
[0058] 3. TLS-ALPN-01 Challenge:
[0059] The ACME server provides a specific token, and the client proves ownership of the domain by configuring a TLS server with a certificate for the domain and presenting the token during the TLS handshake using the Application-Layer Protocol Negotiation (ALPN) extension.
[0060] Another technical area concerns IETF RFC 8555. The below material is the existing high-level call flow of messages exchanges between ACME client and ACME server as per the RFC 8555.
[0061] 1) Client -> Server (New Order Request): The client initiates a new order request to request a new certificate order.
[0062] http POST https: / / acme-server.com / acme / new-order HTTP / 1.1
[0063] Host: acme-server.com
[0064] Content-Type: application / json
[0065] {
[0066] identifiers": [
[0067] {"type": "dns", "value": "example.com"}
[0068] ]
[0069] }
[0070] 2) Server -> Client (New Order Response): The server responds with the details of the new order, including the URLs for authorizations and the finalization step.
[0071] http HTTP / 1.1 201 Created
[0072] Content-Type: application / json
[0073] {
[0074] status": "pending",
[0075] "expires": "2023-01-01T00:00:00Z",
[0076] identifiers": [
[0077] {"type": "dns", "value": "example.com"}
[0078] ],
[0079] authorizations" : ["https: / / acme-server.eom / acme / authz / l "],
[0080] finalize" : "https: / / acme-server.eom / acme / order / l / finalize"
[0081] }
[0082] 3) Client -> Server (Authorization Details Request): The client retrieves details about the authorization to perform the necessary challenges.
[0083] http GET https: / / acme-server.eom / acme / authz / l HTTP / 1.1
[0084] Host: acme-server.com
[0085] 4) Server -> Client (Authorization Details Response): The server responds with the details of the authorization, including the challenges to be completed.
[0086] http HTTP / 1.1 200 OK
[0087] Content-Type: application / Json
[0088] {
[0089] status": "pending",
[0090] "expires": "2023-01-01T00:00:00Z",
[0091] identifier": {"type": "dns", "value": "example.com"},
[0092] "challenges": [
[0093] {"type": "http-01", "URL":"https: / / example.eom / acme / challenge / l", "token": "abcl23"},
[0094] II ... additional challenges
[0095] ]
[0096] }
[0097] 5) Client -> Server (Complete Challenge Request): The client completes the specified challenges (e.g., http-01) to prove control over the domain.
[0098] (This step may involve additional HTTP requests depending on the challenge type.)
[0099] 6) Client -> Server (Finalize Order Request): The client sends a request to finalize the order, providing the public key for the certificate.
[0100] http POST https: / / acme-server.eom / acme / order / l / finalize HTTP / 1.1
[0101] Host: acme-server.com
[0102] Content-Type: application / Json
[0103] {
[0104] csr" : "base64url-encoded-certificate-signing -request"
[0105] }
[0106] 7) Server -> Client (Finalize Order Response): The server responds with the finalization status and the URL to download the certificate.
[0107] http HTTP / 1.1 200 OK
[0108] Content-Type: application / Json
[0109] {
[0110] status": "valid",
[0111] certificate": "https: / / acme-server.eom / acme / order / l / certificate"
[0112] }
[0113] 8) Client -> Server (Download Certificate): The client downloads the issued certificate.
[0114] http GET https: / / acme-server.eom / acme / order / l / certificate HTTP / 1.1
[0115] Host: acme-server.com
[0116] Server -> Client (Certificate Response): The server responds with the issued certificate.
[0117] http HTTP / 1.1 200 OK
[0118] Content-Type: application / pem-certificate-chain
[0119] -—BEGIN CERTIFICATE-—
[0120]
[0121] -—END CERTIFICATE-—
[0122] As per 3GPP release 19 SID, the following is mentioned as part of objectives in S3-235090 (S3-235090, Cisco Systems, et al., “Study of ACME for Automated CertificateManagement in SBA”, 3GPP TSG-SA3 Meeting #113, Chicago, US, 6 - 10 November 2023) and the areas of study include:
[0123] “Existing ACME challenge types and if any new challenge types are needed for 3 GPP use cases, i.e., Creation, deletion, rotation, revocation and storage of the certificates”
[0124] Thus, there is a need to provide new challenge types. Furthermore, the limitations of current available ACME challenge types are mentioned below.
[0125] HTTP-01 Challenge:
[0126] Firewall and Proxy Restrictions: If a web server is behind a firewall or a proxy, it might be challenging for the ACME server to reach the server for the HTTP-01 challenge. This can be an issue in some network configurations.
[0127] Web Server Configuration: Configuring the web server to serve the challenge file and token correctly is crucial. Misconfigurations may lead to validation failures.
[0128] DNS-01 Challenge:
[0129] DNS Provider Limitations: Some DNS providers may have limitations on the frequency of DNS record changes, which could impact the ability to perform frequent domain validations. Also, it implies that firewalls need to open DNS related ports only for that purpose crossing multiple layers, what makes the solution not operationally optimal in real networks.
[0130] TLS-ALPN-01 Challenge:
[0131] Limited Server Support: TLS-ALPN-01 requires support for Application- Layer Protocol Negotiation (ALPN) on the server side. Not all servers may support this feature, which could limit the use of this challenge type.
[0132] ALPN Protocol Compatibility: Some clients and servers may not support or be compatible with certain ALPN protocols, potentially leading to validation failures.
[0133] In addition to the above limitations, there is a complexity in overall communication with respect to a challenge and its response being sent, received, validated at both ACME client and server as described below. For example, an ACME client needs to include the token in its message to Web Server / DNS Server / ALPN Server as part of requested challenge processing, and ACME server again needs to fetch the token from Web Server / DNS Server / ALPN Server to validate the domain ownership. Furthermore, a Webserver / DNSserver / ALPN Server needs to be installed / configured / maintained in the domain, which incurs an extra cost for the operator. Ensuring correctness of the above servers with respect to functionality must be taken care with utmost focus by the operator by configuring the needed resources efficiently.
[0134] All the above limitations might create a bottleneck in SBA architecture, as used in a 5G core (5GC) network to use existing ACME challenge types as specified so far in IETF. Therefore, a new challenge type should be explored as a part of this study for 3GPP in the context of 5G networks.
[0135] Now that problems have been described, an overview of the examples is presented, then further details are presented. As an overview, three approaches / enhancements are proposed to address the above-mentioned limitations. The approaches are as follows: Approach 1 includes a digital signature / MAC based challenge validation using SAN field of the certificate request; Approach 2 has a new identifier type for ACME challenge validation in 5GC; and Approach 3 has a new ACME challenge type for ACME challenge validation. Each of these approaches is now described in order.
[0136] Before proceeding with description of the approaches, some notes are presented. One note is that using an NF is a primary approach that is described herein, but the techniques presented for the NF may be implemented on other network elements even including base stations or central units or other elements of the RAN, for instance. Furthermore, an assumption is made that the 0AM is not public, and is instead in a private operator domain (as shown in FIG. 4). It is possible, however, in the future the 0AM could be public, such as in a PKI system. That possibility may also be encompassed by the examples below.
[0137] An overview of Approach 1 is described first. This approach includes a digital signature / MAC based challenge validation using SAN field of the certificate request.
[0138] In this approach, the OAM / Operator has a digital certificate trusted or issued by ACME server via out-of-band mechanism and the OAM / Operator certificate should be configured in ACME server as a trust anchor to validate the NF’s digital signature with respect to an operator domain (examples of this include vodafone.com, tesla.com).
[0139] Each NF in the operator domain is configured by its 0AM system with a digital signature that is generated using the private key corresponding to the OAM / Operatorcertificate and applies to NF profile parameters such as NFInstancelD, NFType, NFSliceld, and the like. It is noted that it is not important as to which one of these is used. See 3 GPP TS 29.510 for more detailed description of these NF profile parameters. This list may include all NFprofile’s unique parameters defined in 3GPP TS 29.510. This ensures the uniqueness of a signature across various NFs.
[0140] The NF as an ACME client, while requesting the certificate to the ACME server , attaches the pre-configured digital signature by the 0AM system to the SAN field of the CSR (Certificate Signing Request).
[0141] The ACME server extracts the digital signature from the SAN field, and uses the OAM / Operator certificate locally configured for the domain to validate the digital signature.
[0142] On successful validation of digital signature, the ACME server issues the digital certificate to the NF .
[0143] Alternatively, instead of using digital signature, a symmetric key can be configured on both sides, ACME client and ACME server, a MAC is generated on NFProfile parameters such as NFInstancelD, NFType, NFSliceld, or the like using the symmetric key by the ACME client.
[0144] The ACME client sends the MAC in the SAN field while requesting the certificate to the ACME server .
[0145] The ACME server extracts the MAC from the SAN field of the certificate request and uses the symmetric key pre-configured locally to validate the MAC received from NF , upon successful validation, ACME server issues the digital certificate to NF .
[0146] More details about Approach 1 are presented now.
[0147] The detailed flow of http messages for this approach are mentioned below.
[0148] For identifier / domain (e.g., "example.com"), ACME server is preconfigured to use digital signature-based domain validation.
[0149] Similarly, each NF is configured with digital signature generated on NFProfile parameters (e.g., NFInstancelD, NFType, NFSlicelD, or the like) using OAM / Operator private key.
[0150] 1) Client -> Server: The client initiates a new order request to request a new certificate order.
[0151] http POST https: / / acme-server.com / acme / new-order HTTP / 1.1
[0152] Host: acme-server.com
[0153] Content-Type: application / json
[0154] {
[0155] identifiers": [
[0156] {"type": "dns", "value": "example.com"}
[0157] ]
[0158] }
[0159] 2) Server -> Client (New Order Response): The server responds with the details of the new order, including the URLs for authorizations and the finalization step.
[0160] http HTTP / 1.1 201 Created
[0161] Content-Type: application / json
[0162] {
[0163] status": "pending",
[0164] "expires": "2023-01-01T00:00:00Z",
[0165] identifiers": [
[0166] {"type": "dns", "value": "example.com"}
[0167] ],
[0168] authorizations": [],
[0169] finalize" : "https: / / acme-server.eom / acme / order / l / finalize"
[0170] }
[0171] ACME server should send authorizations empty for Digital Signature based authorization and ACME Client should not perform any authorizations if authorizations field is received empty.
[0172] 5) Client -> Server (Finalize Order Request):The client sends a request to finalize the order, providing the public key for the certificate.
[0173] http POST https: / / acme-server.eom / acme / order / l / finalize HTTP / 1.1
[0174] Host: acme-server.com
[0175] Content-Type: application / json
[0176] {
[0177] csr": "base64url-encoded-certificate-signing -request" with SAN Field containing the DigitalSignature
[0178] }
[0179] 6) ACME server validates the Digital Signature in CSR (If possible, ignore this field and not populate in issued certificate, as this field is added only for authentication by ACME server and is not required to be added in the issued certificate by ACME server even present in the CSR).
[0180] Server -> Client (Finalize Order Response): The server responds with the finalization status and the URL to download the certificate.
[0181] http HTTP / 1.1 200 OK
[0182] Content-Type: application / json
[0183] {
[0184] status": "valid",
[0185] certificate": "https: / / acme-server.eom / acme / order / l / certificate"
[0186] }
[0187] 8) Client -> Server (Download Certificate): The client downloads the issued certificate.
[0188] http GET https: / / acme-server.eom / acme / order / l / certificate HTTP / 1.1
[0189] Host: acme-server.com
[0190] Server -> Client (Certificate Response): The server responds with the issued certificate.
[0191] http HTTP / 1.1 200 OK
[0192] Content-Type: application / pem-certificate-chain
[0193] -—BEGIN CERTIFICATE-—
[0194]
[0195] -—END CERTIFICATE-—
[0196] The high-level flow is described now. See FIG. 1, which is a signaling diagram of one example of an approach, Approach 1, of a challenge method that concerns digital signature / MAC based challenge validation using a SAN field of the certificate request. The three main entities that are involved are the NF 99, the 0AM (also referred to as Operator orOAM / Operator) 110, and the ACME server 120. The NF 99 and the 0AM 110 are part of the 5G core (5GC) network 90. A cellular network 1 includes the 5G core network 90, and as described previously, techniques used for the NF 99 may be used by other network elements 105, such as a base station or central unit. The 0AM 110 refers to the processes and functions used in provisioning and managing a network or element within a cellular network, and this functionality is typically controlled by an operator of the network. The following are notes for FIG. 1.
[0197] 1. OAM / Operator 110 has a digital certificate trusted or issued by the ACME server 120. The digital certificate that is trusted or issued by the ACME server 120 is referred to as an 0AM certificate (or a certificate for an 0AM), as it is a certificate for the 0AM 110.
[0198] 2. The ACME server 120 is configured with an 0AM certificate per domain and (2b) the ACME server 120 supports SANBasedDigitalSignature validation. That is, SANBasedDigitalSignature challenge is supported, such that the ACME server 120 will look for the digital signature being part of the SAN (in step 8, described below).
[0199] Reference 130 indicates that there are alternatives (alt) 140 and 150. Alternative 140 includes 3 and 4, while alternative 150 includes 5, 6, and 7. Alternative 140 is described first. This alternative 140 involves the 0AM 110 configuring the digital signature along with NFProfile parameters.
[0200] 3. The OAM / Operator 110 generates a digital signature using a private key associated with 0AM certificate on NF 99 profile parameters (e.g., profile parameters for the NF 99) like NFInstancelD, NFType, NFSliceldlist, and the like. The term “key” (in this step and other steps) in “key NF profile parameters” means the NF profile parameters are important ones, relative to other parameters. In further detail, the NF Profile parameters are used as an input to generate a digital signature using a private key associated with the 0AM certificate. Or, to put it otherwise, the digital signature is generated on the NF Profile Parameters using the private key associated with the 0AM certificate.
[0201] 4. One option can be OAM / Operator 110 configures (at the NF 99) the digital signature along with the NFProfile.
[0202] The alternative 150 is now described. In this alternative, the NF 99 requests the 0AM 110 to generate the digital signature whenever a certificate is needed.
[0203] 5,6,7. NF 99 can request (5) the OAM / Operator 110 to generate (6) the digital signature and the OAM / Operator 110 generates the digital signature using a private key associated with OAM / Operator 110’s certificate on NF profile parameters like NFInstancelD, NFType, NFSliceldlist, and the like, and sends (7) the digital signature to NF 99.
[0204] 8. NF 99 generates a CSR (Certificate Signing Request) with the addition of the digital signature in the SAN field of CSR and sends the CSR to the ACME server 120.
[0205] 9. ACME server 120 retrieves (9a) the 0AM Certificate associated with the domain present in the CSR request and performs (i) a validation that validates (9b) the digital signature received using the 0AM certificate. Once the digital signature is validated, ACME server 120 checks via another (ii) validation that the parameters in the digital signature match with the parameters in certificate request received from NF 99, e.g., the CSR parameters such as NFInstancelD, NFType. This is typically a one-to-one match, meaning the NFInstancelD in the digital signature matches with the NFInstancelD in certificate request, the NFType in the digital signature matches with the NFType in certificate request, and the like. The ACME server 120, on successful validation (of both (i) and (ii)), issues the certificate (9c).
[0206] 10. Upon successful validation, the ACME server 120 issues a TLS / SSL certificate to NF 99 via the signaling of the TLS / SSL certificate.
[0207] An overview of Approach 2 is now described. In this approach, a new identifier type is used for ACME challenge validation in 5GC.
[0208] In this approach, the 0AM / Operator has a digital certificate trusted or issued by ACME server 120 via out-of-band mechanism and the OAM / Operator 110 certificate should be configured in ACME server 120 as a trust anchor to validate the NF 99 ’s digital signature with respect to an operator domain (examples of this include vodafone.com, tesla.com).
[0209] Each NF 99 in the operator domain is configured with a digital signature that is generated using a private key corresponding to the OAM / Operator 110 certificate and applies to NF 99 profile parameters such as NFInstancelD, NFType, NFSliceld or the like. This ensures the uniqueness of signature across various NFs.
[0210] An NF 99 while, requesting for a certificate to the ACME server 120, presents a new identifier whose type is referred to as NFInstancelD (similar to other identifiers as per RFC 8555 such as dns and ip) and its value is plain NFInstancelD + digital signature configuredat NF 99 by the OAM / Operator 110. The new identifier can be considered to have a certain identifier type of NFInstancelD.
[0211] The ACME server 120 reads the identifier type (NFInstancelD) and its value (plain NFInstancelD + digital signature), validates the digital signature using the OAM / Operator 110 certificate against the plain NFInstancelD. The variable NFInstancelD represents an identifier, that is globally unique at least where the NF is registered, and therefore us used to identify an instance of the network element.
[0212] Once the validation is successful, ACME server 120 provides the certificate to the ACME client.
[0213] Additional details about Approach 2 are described now.
[0214] For identifier / domain (e.g., "example.com"), ACME server 120 is preconfigured to use digital signature-based domain validation.
[0215] Similarly, each NF 99 is configured with digital signature generated on NFProfile parameters (NFInstancelD, NFType, NFSlicelD, and the like) using OAM / Operator 110 private key.
[0216] 1) Client To Server:
[0217] http POST https: / / acme-server.com / acme / new-order HTTP / 1.1
[0218] Host: acme-server.com
[0219] Content-Type: application / json
[0220] {
[0221] identifiers": [
[0222] {"type": "dns", "value": "example.com"},
[0223] {"type": "NFInstancelD", "value": <NFInstanceIDValue>@<Digital Signature>}
[0224] ]
[0225] }
[0226] Note: The value of NFInstancelD can be extended to provide more parameters in addition to NFInstancelD (Examples include NFType, NFSlicelD, and the like)
[0227] 2) Server -> Client (New Order Response): The server responds with the details of the new order, including the URLs for authorizations and the finalization step.
[0228] http HTTP / 1.1 201 Created
[0229] Content-Type: application / json
[0230] {
[0231] status": "pending",
[0232] "expires": "2023-01-01T00:00:00Z",
[0233] identifiers": [
[0234] {"type": "dns", "value": "example.com"}
[0235]
[0236] ],
[0237] authorizations": [""],
[0238] finalize" : "https: / / acme-server.eom / acme / order / l / finalize"
[0239] }
[0240] 3) Client -> Server (Finalize Order Request): The client sends a request to finalize the order, providing the public key for the certificate.
[0241] http POST https: / / acme-server.eom / acme / order / l / finalize HTTP / 1.1
[0242] Host: acme-server.com
[0243] Content-Type: application / json
[0244] {
[0245] csr" : "base64url-encoded-certificate-signing -request"
[0246] }
[0247] Note: The NFInstancelD from the SAN field of the csr should be matched with the identifier value of NFInstancelD to ensure NF 99 is sending its own NFInstancelD.
[0248] 4) Server -> Client (Finalize Order Response): The server responds with the finalization status and the URL to download the certificate.
[0249] http HTTP / 1.1 200 OK
[0250] Content-Type: application / json
[0251] {
[0252] status": "valid",
[0253] certificate": "https: / / acme-server.eom / acme / order / l / certificate"
[0254] }
[0255] 5) Client -> Server (Download Certificate): The client downloads the issued certificate.
[0256] http GET https: / / acme-server.eom / acme / order / l / certificate HTTP / 1.1
[0257] Host: acme-server.com
[0258] Server -> Client (Certificate Response): The server responds with the issued certificate.
[0259] http HTTP / 1.1 200 OK
[0260] Content-Type: application / pem-certificate-chain
[0261] -—BEGIN CERTIFICATE-—
[0262]
[0263] -—END CERTIFICATE-—
[0264] The detailed flow diagram is mentioned below. Refer to FIG. 2, which is a signaling diagram of one example of an approach, Approach 2, of a challenge method that concerns a new identifier type for ACME challenge validation in 5GC.
[0265] 1. The OAM / Operator 110 has a digital certificate trusted by the ACME server 120.
[0266] 2. The ACME server 120 is configured with an 0AM certificate per domain and ACME server 120 supports (2b) identifier-based digital signature validation (e.g., per domain).
[0267] Reference 230 indicates that there are alternatives (alt) 240 and 250. Alternative 240 includes 3 and 4, while alternative 250 includes 5, 6, and 7. Alternative 240 is described first. This alternative 240 involves the 0AM 110 configuring the digital signature along with NFProfile parameters.
[0268] 3. OAM / Operator 110 generates a digital signature using a private key associated with an 0AM certificate on NF 99 profile parameters like NFInstancelD, NFType, NFSliceldlist, and the like.
[0269] 4. One option can be OAM / Operator 110 configures (at the NF 99) the digital signature along with the NFProfile.
[0270] The alternative 250 is now described. In this alternative, the NF 99 requests the 0AM 110 to generate the digital signature whenever a certificate is needed.
[0271] 5,6,7. The NF 99 can request (5) the OAM / Operator 110 to generate the digital signature, the OAM / Operator 110 generates (6) the digital signature using the private key associated with OAM / Operator 110’s certificate on NF profile parameters like NFInstancelD, NFType, NFSliceldlist, and the like, and sends (7) the digital signature to the NF 99.
[0272] 8. The ACME Client (i.e., NF 99), as part of certificate request procedure, creates a new identifier called NFInstancelD with a value having a plain (i.e., in cleartext) NFInstancelD and digital signature configured by 0AM. The NFInstancelD is a type of identifier, which contains a clear text value. As previously described, the digital signature is generated on this NFInstancelD, and the ACME server is expected to validate the plain NFInstancelD with that of digital signature, post decryption. It is noted this signaling includes (incl.) indication of a domain. That is, in the current New Order Request, domain is already present as a parameter. At least the use of this parameter and its signature in the call flow specified by ACME IETF RFC is part of the exemplary embodiment of Approach 2 herein.
[0273] 9. The ACME client, NF 99, on successful response from ACME server 120, sends CSR request to the ACME server 120. The ACME server 120 (9a) retrieves the 0AM certificate locally associated with the domain present in the New Order request, and (9b) validates the digital signature received in an identifier using the 0AM certificate and validates NFInstancelD in the digital signature matches with the plain NFInstancelD received in the identifier value.
[0274] Steps 10-12 are used to ensure the identifier mentioned in the New Order Request from step 8 matches with that of in the CSR Request from step 10.
[0275] 10. The NF 99 sends an ACME (CSR) request, e.g., which has anNFInstancelD in the SAN field, to the ACME server 120.
[0276] 11. Upon successful validation, the ACME server 120 issues a certificate toNF 99. That is, the ACME server 120 validates that the NFInstancelD in the CSR request matches with the NFInstancelD in the identifier field (e.g., in the new identifier type “NFInstancelD” in step 8).
[0277] 12. The ACME server 120 sends the TLS / SSL certificate to the NF 99.
[0278] Approach 3 is now presented as an overview. The approach involves a new ACME challenge type for ACME challenge validation.
[0279] In this approach, the 0AM / Operator has a digital certificate trusted by ACME server 120 or issued by ACME server 120 via an out-of-band mechanism and the OAM / Operator 110 certificate should be configured in ACME server 120 as a trust anchor.
[0280] Each NF 99 in the operator domain is configured with a digital signature that is generated using the private key corresponding to the OAM / Operator 110 certificate and applies to several NF 99 profile parameters such as NFInstancelD, NFType, NFSliceld, or the like.
[0281] The ACME server 120 is preconfigured to use DigitalSignature based challenge for a particular domain.
[0282] As a part of certificate request procedure, NF 99 receives an URL with new challenge type called DigitalSignature challenge from ACME server 120.
[0283] As part of DigitalSignature challenge, NF 99 writes the plain NFInstancelD and digital signature configured by OAM / Operator 110 to the URL provided by the ACME server 120.
[0284] The ACME server 120 validates the digital signature and on successful validation, issues the certificate.
[0285] More details about Approach 3 are presented now.
[0286] For identifier / domain (e.g., "example.com"), ACME server 120 is preconfigured to use digital signature-based domain validation.
[0287] Similarly, each NF 99 is configured with digital signature generated on NFProfile parameters (NFInstancelD, NFType, NFSlicelD, and the like) using OAM / Operator 110 private key.
[0288] 1) Client -> Server (New Order Request): The client initiates a new order request to request a new certificate order.
[0289] http POST https: / / acme-server.com / acme / new-order HTTP / 1.1
[0290] Host: acme-server.com
[0291] Content-Type: application / json
[0292] {
[0293] identifiers": [
[0294] {"type": "dns", "value": "example.com"}
[0295] ]
[0296] }
[0297] For "example.com" ACME server 120 is preconfigured to use DigitalSignature Challenge.
[0298] 2) Server -> Client (New Order Response): The server responds with the details of the new order, including the URLs for authorizations and the finalization step.
[0299] http HTTP / 1.1 201 Created
[0300] Content-Type: application / json
[0301] {
[0302] status": "pending",
[0303] "expires": "2023-01-01T00:00:00Z",
[0304] identifiers": [
[0305] {"type": "dns", "value": "example.com"}
[0306] ],
[0307] authorizations" : ["https: / / acme-server.eom / acme / authz / l "],
[0308] finalize" : "https: / / acme-server.eom / acme / order / l / finalize"
[0309] }
[0310] 3) Client -> Server (Authorization Details Request):The client retrieves details about the authorization to perform the necessary challenges.
[0311] http GET https: / / acme-server.eom / acme / authz / l HTTP / 1.1
[0312] Host: acme-server.com
[0313] Server -> Client (Authorization Details Response): The server responds with the details of the authorization, including the challenges to be completed.
[0314] http HTTP / 1.1 200 OK
[0315] Content-Type: application / json
[0316] {
[0317] status": "pending",
[0318] "expires": "2023-01-01T00:00:00Z",
[0319] identifier": {"type": "dns", "value": "example.com"},
[0320] "challenges": [
[0321] {"type": "DigitalSignature", "url": "https: / / acme-
[0322] H ... additional challenges
[0323] ]
[0324] }
[0325] 4) Client -> Server (Complete Challenge Request): The client completes the challenge on the url provided by the ACME server 120, keeping plain NFInstancelD and digital signature of NFInstancelD using OAM / Operator’s 110 private key. ACME server 120 validates the challenge.
[0326] 5) Client -> Server (Finalize Order Request): The client sends a request to finalize the order, providing the public key for the certificate.
[0327] http POST https: / / acme-server.eom / acme / order / l / finalize HTTP / 1.1
[0328] Host: acme-server.com
[0329] Content-Type: application / json
[0330] {
[0331] csr" : "base64url-encoded-certificate-signing -request"
[0332] }
[0333] Note: The NFInstancelD from the SAN field of the csr should be matched with the challenge content to ensure NF 99 is sending its own NFInstancelD in CSR.
[0334] 6) Server -> Client (Finalize Order Response): The server responds with the finalization status and the URL to download the certificate.
[0335] http HTTP / 1.1 200 OK
[0336] Content-Type: application / json
[0337] {
[0338] status": "valid",
[0339] certificate": "https: / / acme-server.eom / acme / order / l / certificate"
[0340] }
[0341] 8) Client -> Server (Download Certificate): The client downloads the issued certificate.
[0342] http GET https: / / acme-server.eom / acme / order / l / certificate HTTP / 1.1
[0343] Host: acme-server.com
[0344] Server -> Client (Certificate Response): The server responds with the issued certificate.
[0345] http HTTP / 1.1 200 OK
[0346] Content-Type: application / pem-certificate-chain
[0347] -—BEGIN CERTIFICATE-—
[0348]
[0349] -—END CERTIFICATE-—
[0350] The detailed flows are mentioned below. Turn to FIG. 3, which is a signaling diagram of one example of an approach, Approach 3, of a challenge method that concerns a new ACME challenge type for ACME challenge validation.
[0351] 1. The OAM / Operator 110 has a digital certificate trusted by the ACME server 120.
[0352] 2. The ACME server 120 is configured with 0AM certificate per domain and the ACME server 120 supports (2b) a DigitalSignature challenge type for the domain.
[0353] Reference 330 indicates that there are alternatives (alt) 340 and 350. Alternative 340 includes 3 and 4, while alternative 350 includes 5, 6, and 7. Alternative 340 is described first. This alternative 340 involves the 0AM 110 configuring the digital signature along with NFProfile parameters.
[0354] 3. The OAM / Operator 110 generates a digital signature using a private key associated with an 0AM certificate on NF 99 profile parameters like NFInstancelD, NFType, NFSliceldlist, and the like.
[0355] 4. One option can be OAM / Operator 110 configures (to the NF 99) the digital signature along with the NFProfile.
[0356] The alternative 350 is now described. In this alternative, the NF 99 requests the 0AM 110 to generate the digital signature whenever a certificate is needed.
[0357] 5,6,7. The NF 99 can request (5) the OAM / Operator 110 to generate (6) the digital signature and OAM / Operator 110 generates digital signature using the private key associated with the OAM / Operator 110’s certificate on NF profile parameters like NFInstancelD, NFType, NFSliceldlist, and the like, and sends (7) the digital signature to NF 99.
[0358] 8. ACME Client sends a new order request as part of a certificate request procedure to the ACME server 120. The new order request, as previously described, includes an indication of a domain.
[0359] 9. The ACME server 120 responds with the DigitalSignature challenge type and also provides the url to upload the data.
[0360] 10. The ACME client (i.e., the NF 99) writes the plain NFInstancelD and digital signature configured at the NF 99 by the operator at the url as part of DigitalSignature challenge.
[0361] 11. The ACME server 120 retrieves (I la) the 0AM Certificate associated with the domain present in the New Order request and validates the digital signature received using 0AM certificate. Once the digital signature is validated, ACME server 120 checks if the NFInstancelD in digital signature matches with the plain NFInstancelD. That is, the ACME server 120 validates (11b) the digital signature received in the url using the 0AM certificate and validates the NFInstancelD in the digital signature matches with the plain NFInstancelD.
[0362] Steps 12-14 are used to ensure the identifier mentioned in the New Order Request of step 8 matches with that of in the CSR Request of step 12.
[0363] 12. The ACME Client (AF 99) sends the CSR request to the ACME server120.
[0364] 13. The ACME server 120 validates the NFInstancelD received in the CSR request by matching with the NFInstancelD in the url.
[0365] 14. Upon successful validation, the ACME server 120 issues certificate to NF99 via a TLS / SSL certificate message.
[0366] Turning to FIG. 4, this figure shows a block diagram of one possible and nonlimiting example of a cellular network 1. A number of network elements are shown in the cellular network of FIG. 4: a base station 70; a core network 90. The 0AM 110 is part of the core network 90 in this example. The network element 105 can be the base station 70 (or a similar element) or a network function 99. The 0AM 110 and the ACME server 120 are part of an operator domain 410, which is private and not public. There is an assumption that the operator domain 410 is not public, but in the future at least the ACME server 120 may be public such as a PKI system. The ACME server 120 is typically part of the data network 91.
[0367] In FIG. 4, the base station 70, as a network element of the cellular network 1, provides a UE 10, via radio link 11, access to cellular network 1 and to the data network 91 via the core network 90 (e.g., via a user plane function (UPF) 99 of the core network 90). As such, the base station 70 may be considered to be an access node, which provides access by UE(s) to the cellular network 1. The base station 70 is illustrated as having one or more antennas 58. In general, the base station 70 may be referred to as RAN node 70, although many will make reference to this as a gNB (gNode B, a base station for NR, new radio) instead. There are, however, many other examples of RAN nodes including an eNB (evolved Node B) or TRP (Transmission-Reception Point). The RAN nodes may also be separated into central units and distributed units (possibly with corresponding radio units). Correspondingly, the network element 105 may include the base station 70 or a central unit or another element. The base station 70 includes one or more processors 73, one or more memories 75, and other circuitry 76. The other circuitry 76 includes one or more receivers (Rx(s)) 77 and one or more transmitters (Tx(s)) 78. A program 72 is used to cause the base station 70 to perform the operations described herein.
[0368] Two or more base stations 70 communicate using, e.g., link(s) 79. The link(s) 79 may be wired or wireless or both and may implement, e.g., an Xn interface for 5G (fifth generation), an X2 interface for LTE (Long Term Evolution), or other suitable interface for other standards.
[0369] The cellular network 1 may include a core network 90, as a second network element or elements, that may include core network functionality, and which provide connectivity via a link or links 81 with a data network 91, such as a telephone network and / or a data communications network (e.g., the Internet). The core network 90 includes one or more processors 93, one or more memories 95, and other circuitry 96. The other circuitry 96 includes one or more receivers (Rx(s)) 97 and one or more transmitters (Tx(s)) 98. A program 92 is used to cause the core network 90 to perform the operations described herein.
[0370] The core network 90 could be a 5GC (5G core network). The core network 90 can implement or comprise multiple network functions (NF 99(s)) 99, and the program 92 may comprise one or more of the NFs 99. A 5G core network may use hardware such as memory and processors and a virtualization layer. It could be a single standalone computing system, adistributed computing system, or a cloud computing system. The NFs 99, as network elements, of the core network could be containers or virtual machines running on the hardware of the computing system(s) making up the core network 90.
[0371] Core network functionality for 5G may include access and mobility management functionality that is provided by a network function 99 such as an access and mobility management function (AMF), session management functionality that is provided by a network function such as a session management function (SMF). Core network functionality for access and mobility management in an LTE (Long Term Evolution) network may be provided by an MME (Mobility Management Entity) and / or SGW (Serving Gateway) functionality, which routes data to the data network. Many others are possible, as illustrated by the examples in FIG. 4: AMF; SMF; MME; SGW; GMLC (Gateway Mobile Location Center); LMF (Location Management Function); UDM (Unified Data Management) / UDR (Unified Data Repository); NRF (Network Repository Function); and / or E-SMLC (Evolved Serving Mobile Location Center). These are merely exemplary core network functionality that may be provided by the core network 90, and note that both 5G and LTE core network functionality might be provided by the core network 90. The base station 70 is coupled via a backhaul link 31 to the core network 90. The base station 70 and the core network 90 may include an NG (Next Generation) interface for 5G, or an SI interface for LTE, or other suitable interface for other radio access technologies for communicating via the backhaul link 31.
[0372] In the data network 91, there is a computer-readable medium 94. The computer-readable medium 94 contains instructions that, when downloaded and installed into the memories 15, 75, or 95 of the corresponding UE 10, base station 70, and / or core network element(s) 90, and executed by processor(s) 13, 73, or 93, cause the respective device to perform corresponding actions described herein. The computer-readable medium 94 may be implemented in other forms, such as via a compact disc or memory stick.
[0373] The programs 12, 72, and 92 contain instructions stored by corresponding one or more memories 15, 75, or 95. These instructions, when executed by the corresponding one or more processors 13, 73, or 93, cause the corresponding apparatus 10, 70, or 90, to perform the operations described herein. The computer readable memories 15, 75, or 95 are circuitry and may be of any type suitable to the local technical environment and may be implemented usingany suitable data storage technology, such as semiconductor-based memory devices, flash memory, firmware, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The computer readable memories 15, 75, and 95 may be means for performing storage functions. The processors 13, 73, and 93, are circuitry and may be of any type suitable to the local technical environment. For example, these processors may include one or more of general-purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), processors based on a multi-core processor architecture, and may also include specialized circuits such as field-programmable gate arrays (FPGAs), application specific circuits (ASICs), signal processing devices and other devices, or combinations of these devices, as non-limiting examples. The processors 13, 73, and 93 may be means for causing their respective apparatus to perform functions, such as those described herein. Particularly, for any apparatus having means to perform functions described herein, the means may include at least one processor, and at least one memory storing instructions that, when executed by at least one processor, cause the performance of the apparatus.
[0374] The receivers 17, 77, and 97, and the transmitters 18, 78, and 98 may implement wired or wireless interfaces. The receivers and transmitters may be grouped together as transceivers.
[0375] The cellular network 1 may implement network virtualization, which is the process of combining hardware and software network resources and network functionality into a single, software-based administrative entity, a virtual network. Network virtualization involves platform virtualization, often combined with resource virtualization. Network virtualization is categorized as either external, combining many networks, or parts of networks, into a virtual unit, or internal, providing network-like functionality to software containers on a single system. Note that the virtualized entities (such as network functions 99) that result from the network virtualization are still implemented, at some level, using hardware such as processors 73 and / or 93 and memories 75 and / or 95, and also such virtualized entities create technical effects.
[0376] Without in any way limiting the scope, interpretation, or application of the claims appearing below, a technical effect and / or advantage of one or more of the example embodiments disclosed herein is that the limitations mentioned above for existing challenge types (http-01, DNS -01, ALPN-01) are not present with our proposed challenge types.
[0377] The following are additional examples.
[0378] Example 1. A method, comprising: receiving, at an automated certificate management environment server from a network element in a cellular network, a certificate signing request comprising indication of a domain and a subject alternative name comprising a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with the domain present in the certificate Signing Request; performing, by the automated certificate management environment server, a validation by validating the digital signature using the retrieved certificate for the operation, administration, and maintenance and validating that one or more parameters encoded in the digital signature match with corresponding one or more parameters from the certificate Signing Request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validation.
[0379] Example 2. The method according to example 1, further comprising: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the certificate signing request.
[0380] Example 3. The method according to any of examples 1 to 2, wherein: the method further comprises determining, prior to receiving the certificate signing request, by the automated certificate management environment server that subject alternative name-based digital signature challenge is supported; and the receiving comprises, based on the subject alternative name-based digital signature challenge being supported, examining the subject alternative name in the certificate signing request for the digital signature.
[0381] Example 4. The method according to any of examples 1 to 3, wherein the one or more parameters from the certificate signing request comprise one or more of NFInstancelD, NFType, or NFSlicelDlist.
[0382] Example 5. A method, comprising: generating, by an operation, administration, and maintenance in a core network of a cellular network, a digital signature using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for a network element that is in the cellular network; andcommunicating, by the operation, administration, and maintenance, at least the digital signature to the network element.
[0383] Example 6. The method according to example 5, further comprising: communicating, by the operation, administration, and maintenance with an automated certificate management environment server, to configure the certificate for the operation, administration, and maintenance prior to generating the digital signature.
[0384] Example 7. The method according to any of examples 5 to 6, wherein the communicating, by the operation, administration, and maintenance, at least the digital signature to the network element comprises configuring, on the network element, a profile for the network element, the profile comprising the digital signature.
[0385] Example 8. The method according to example 7, wherein the profile further comprises one or more parameters and the digital signature comprises the one or more parameters.
[0386] Example 9. The method according to any of examples 5 to 6, wherein: the method further comprises: receiving, by the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the generating the digital signature is performed in response to the receiving the message; and the communicating, by the operation, administration, and maintenance, at least the digital signature to the network element comprises: sending, by the operation, administration, and maintenance to the network element, a message comprising the generated digital signature.
[0387] Example 10. A method, comprising: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for an operation, administration, and maintenance and using one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a certificate signing request comprising indication of a domain and a subject alternative name comprising the digital signature; and receiving, by the network element from the automated certificate management environment server and in response to the certificate Signing Request, a transport layer security / secure sockets layer certificate issued by the automated certificate management environment server.
[0388] Example 11. The method according to example 10, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature and the one or more profile parameters for the network element.
[0389] Example 12. The method according to example 10, wherein the method further comprises: sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0390] Example 13. A method, comprising: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; validating, by the automated certificate management environment server, the digital signature using the retrieved certificate for the operation, administration, and maintenance and performing a validation of the plain identifier by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier from the first request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0391] Example 14. The method according to example 13, further comprising: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the first request.
[0392] Example 15. The method according to any of examples 13 to 14, wherein: the method further comprises determining, prior to receiving the first request, by the automatedcertificate management environment server that identifier based digital signature is supported for the domain; and the receiving the first request comprises, based on the identifier based digital signature being supported, examining the first request for the plain identifier.
[0393] Example 16. A method, comprising: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0394] Example 17. The method according to example 16, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature and the one or more profile parameters for the network element.
[0395] Example 18. The method according to example 16, wherein: the method further comprises: sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0396] Example 19. A method, comprising: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request as part of a certificate request procedure; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; sending, by the automated certificate management environment server to the network element, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server;validating, by the automated certificate management environment server, a digital signature retrieved using the url and the certificate for the operation, administration, and maintenance, and performing a validation of a plain identifier, retrieved using the url and having a certain identifier type and used to identify an instance of the network element, by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier retrieved from the url; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0397] Example 20. The method according to example 19, further comprising: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the first request.
[0398] Example 21. The method according to any of examples 19 to 20, wherein: the method further comprises determining, prior to receiving the certificate signing request, by the automated certificate management environment server that a digital signal challenge type is supported for the domain; and the sending the response having the challenge type of the digital signature and having the url of the automated certificate management environment server is performed based on the digital signal challenge type being supported and the first request being received.
[0399] Example 22. A method, comprising: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with an operation, administration, and maintenance certificate on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request as part of a certificate request procedure; receiving, by the network element and from the automated certificate management environment server, a response having a challenge type of a digital signature and having an url of the automated certificatemanagement environment server; writing, by the network element and to the automated certificate management environment server by using the url, a plain identifier having a certain identifier type and used to identify an instance of the network element, and the digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0400] Example 23. The method according to example 16, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature.
[0401] Example 24. The method according to example 16, wherein: the method further comprises sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0402] Example 25. The method according to any of method examples 1 to 24, where the network element is a network function in the core network of the cellular network.
[0403] Example 26. A computer program, comprising instructions for performing the methods of any of examples 1 to 25, when the computer program is run on an apparatus.
[0404] Example 27. The computer program according to example 26, wherein the computer program is a computer program product comprising a computer-readable medium bearing instructions embodied therein for use with the apparatus.
[0405] Example 28. The computer program according to example 26, wherein the computer program is directly loadable into an internal memory of the apparatus.
[0406] Example 29. An apparatus, comprising means for performing: receiving, at an automated certificate management environment server from a network element in a cellular network, a certificate signing request comprising indication of a domain and a subject alternative name comprising a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that isassociated with the domain present in the certificate Signing Request; performing, by the automated certificate management environment server, a validation by validating the digital signature using the retrieved certificate for the operation, administration, and maintenance and validating that one or more parameters encoded in the digital signature match with corresponding one or more parameters from the certificate Signing Request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validation.
[0407] Example 30. The apparatus according to example 29, wherein the means are further configured for performing: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the certificate signing request.
[0408] Example 31. The apparatus according to any of examples 29 to 30, wherein: the means are further configured for performing determining, prior to receiving the certificate signing request, by the automated certificate management environment server that subject alternative name-based digital signature challenge is supported; and the receiving comprises, based on the subject alternative name-based digital signature challenge being supported, examining the subject alternative name in the certificate signing request for the digital signature.
[0409] Example 32. The apparatus according to any of examples 29 to 31, wherein the one or more parameters from the certificate signing request comprise one or more of NFInstancelD, NFType, or NFSlicelDlist.
[0410] Example 33. An apparatus, comprising means for performing: generating, by an operation, administration, and maintenance in a core network of a cellular network, a digital signature using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for a network element that is in the cellular network; and communicating, by the operation, administration, and maintenance, at least the digital signature to the network element.
[0411] Example 34. The apparatus according to example 33, wherein the means are further configured for performing: communicating, by the operation, administration, and maintenance with an automated certificate management environment server, to configure thecertificate for the operation, administration, and maintenance prior to generating the digital signature.
[0412] Example 35. The apparatus according to any of examples 33 to 34, wherein the communicating, by the operation, administration, and maintenance, at least the digital signature to the network element comprises configuring, on the network element, a profile for the network element, the profile comprising the digital signature.
[0413] Example 36. The apparatus according to example 35, wherein the profile further comprises one or more parameters and the digital signature comprises the one or more parameters.
[0414] Example 37. The apparatus according to any of examples 33 to 36, wherein: the means are further configured for performing: receiving, by the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the generating the digital signature is performed in response to the receiving the message; and the communicating, by the operation, administration, and maintenance, at least the digital signature to the network element comprises: sending, by the operation, administration, and maintenance to the network element, a message comprising the generated digital signature.
[0415] Example 38. An apparatus, comprising means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for an operation, administration, and maintenance and using one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a certificate signing request comprising indication of a domain and a subject alternative name comprising the digital signature; and receiving, by the network element from the automated certificate management environment server and in response to the certificate Signing Request, a transport layer security / secure sockets layer certificate issued by the automated certificate management environment server.
[0416] Example 39. The apparatus according to example 38, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature and the one or more profile parameters for the network element.
[0417] Example 40. The apparatus according to example 38, wherein the means are further configured for performing: sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0418] Example 41. An apparatus, comprising means for performing: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; validating, by the automated certificate management environment server, the digital signature using the retrieved certificate for the operation, administration, and maintenance and performing a validation of the plain identifier by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier from the first request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0419] Example 42. The apparatus according to example 41, wherein the means are further configured for performing: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the first request.
[0420] Example 43. The apparatus according to any of examples 41 to 42, wherein: the means are further configured for performing determining, prior to receiving the first request, by the automated certificate management environment server that identifier based digital signature is supported for the domain; and the receiving the first request comprises, based on theidentifier based digital signature being supported, examining the first request for the plain identifier.
[0421] Example 44. An apparatus, comprising means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0422] Example 45. The apparatus according to example 44, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature and the one or more profile parameters for the network element.
[0423] Example 46. The apparatus according to example 44, wherein: the means are further configured for performing: sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0424] Example 47. An apparatus, comprising means for performing: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request as part of a certificate request procedure; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; sending, by the automated certificate management environment server to the network element, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; validating, by the automated certificate management environment server, adigital signature retrieved using the url and the certificate for the operation, administration, and maintenance, and performing a validation of a plain identifier, retrieved using the url and having a certain identifier type and used to identify an instance of the network element, by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier retrieved from the url; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0425] Example 48. The apparatus according to example 47, wherein the means are further configured for performing: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the first request.
[0426] Example 49. The apparatus according to any of examples 47 to 48, wherein: the means are further configured for performing determining, prior to receiving the certificate signing request, by the automated certificate management environment server that a digital signal challenge type is supported for the domain; and the sending the response having the challenge type of the digital signature and having the url of the automated certificate management environment server is performed based on the digital signal challenge type being supported and the first request being received.
[0427] Example 50. An apparatus, comprising means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with an operation, administration, and maintenance certificate on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request as part of a certificate request procedure; receiving, by the network element and from the automated certificate management environment server, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; writing, by the network element andto the automated certificate management environment server by using the url, a plain identifier having a certain identifier type and used to identify an instance of the network element, and the digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0428] Example 51. The apparatus according to example 50, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature.
[0429] Example 52. The apparatus according to example 50, wherein: the means are further configured for performing sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0430] Example 53. The apparatus according to any of apparatus examples 29 to 52, where the network element is a network function in the core network of the cellular network.
[0431] Example 54. The apparatus of any preceding apparatus example, wherein the means comprises: at least one processor; and at least one memory storing instructions that, when executed by at least one processor, cause the performance of the apparatus.
[0432] Example 55. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an automated certificate management environment server from a network element in a cellular network, a certificate signing request comprising indication of a domain and a subject alternative name comprising a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with the domain present in the certificate Signing Request; performing, by the automated certificate management environment server, a validation by validating the digital signature using the retrieved certificate for the operation, administration, and maintenance and validating that one or more parameters encoded in thedigital signature match with corresponding one or more parameters from the certificate Signing Request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validation.
[0433] Example 56. The apparatus according to example 55, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the certificate signing request.
[0434] Example 57. The apparatus according to any of examples 55 to 56, wherein: the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform determining, prior to receiving the certificate signing request, by the automated certificate management environment server that subject alternative name-based digital signature challenge is supported; and the receiving comprises, based on the subject alternative name-based digital signature challenge being supported, examining the subject alternative name in the certificate signing request for the digital signature.
[0435] Example 58. The apparatus according to any of examples 55 to 57, wherein the one or more parameters from the certificate signing request comprise one or more of NFInstancelD, NFType, or NFSlicelDlist.
[0436] Example 59. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: generating, by an operation, administration, and maintenance in a core network of a cellular network, a digital signature using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for a network element that is in the cellular network; and communicating, by the operation, administration, and maintenance, at least the digital signature to the network element.
[0437] Example 60. The apparatus according to example 59, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: communicating, by the operation, administration, and maintenance with an automated certificate management environment server, to configure thecertificate for the operation, administration, and maintenance prior to generating the digital signature.
[0438] Example 61. The apparatus according to any of examples 59 to 60, wherein the communicating, by the operation, administration, and maintenance, at least the digital signature to the network element comprises configuring, on the network element, a profile for the network element, the profile comprising the digital signature.
[0439] Example 62. The apparatus according to example 61, wherein the profile further comprises one or more parameters and the digital signature comprises the one or more parameters.
[0440] Example 63. The apparatus according to any of examples 59 to 62, wherein: the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, by the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the generating the digital signature is performed in response to the receiving the message; and the communicating, by the operation, administration, and maintenance, at least the digital signature to the network element comprises: sending, by the operation, administration, and maintenance to the network element, a message comprising the generated digital signature.
[0441] Example 64. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for an operation, administration, and maintenance and using one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a certificate signing request comprising indication of a domain and a subject alternative name comprising the digital signature; and receiving, by the network element from the automated certificate management environment server and in response to the certificate Signing Request, a transport layer security / secure sockets layer certificate issued by the automated certificate management environment server.
[0442] Example 65. The apparatus according to example 64, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature and the one or more profile parameters for the network element.
[0443] Example 66. The apparatus according to example 64, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0444] Example 67. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; validating, by the automated certificate management environment server, the digital signature using the retrieved certificate for the operation, administration, and maintenance and performing a validation of the plain identifier by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier from the first request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0445] Example 68. The apparatus according to example 67, wherein the one or more memories further store instructions that, when executed by the one or more processors,cause the apparatus at least to perform: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the first request.
[0446] Example 69. The apparatus according to any of examples 67 to 68, wherein: the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform determining, prior to receiving the first request, by the automated certificate management environment server that identifier based digital signature is supported for the domain; and the receiving the first request comprises, based on the identifier based digital signature being supported, examining the first request for the plain identifier.
[0447] Example 70. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0448] Example 71. The apparatus according to example 70, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature and the one or more profile parameters for the network element.
[0449] Example 72. The apparatus according to example 70, wherein: the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: sending, to the operation, administration, andmaintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0450] Example 73. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request as part of a certificate request procedure; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; sending, by the automated certificate management environment server to the network element, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; validating, by the automated certificate management environment server, a digital signature retrieved using the url and the certificate for the operation, administration, and maintenance, and performing a validation of a plain identifier, retrieved using the url and having a certain identifier type and used to identify an instance of the network element, by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier retrieved from the url; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
[0451] Example 74. The apparatus according to example 73, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the first request.
[0452] Example 75. The apparatus according to any of examples 73 to 74, wherein: the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform determining, prior to receiving the certificate signing request, by the automated certificate management environment server that a digital signal challenge type is supported for the domain; and the sending the response having the challenge type of the digital signature and having the url of the automated certificate management environment server is performed based on the digital signal challenge type being supported and the first request being received.
[0453] Example 76. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with an operation, administration, and maintenance certificate on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request as part of a certificate request procedure; receiving, by the network element and from the automated certificate management environment server, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; writing, by the network element and to the automated certificate management environment server by using the url, a plain identifier having a certain identifier type and used to identify an instance of the network element, and the digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
[0454] Example 77. The apparatus according to example 76, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature.
[0455] Example 78. The apparatus according to example 76, wherein: the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
[0456] Example 79. The apparatus according to any of apparatus examples 55 to 78, where the network element is a network function in the core network of the cellular network.
[0457] As used in this application, the term “circuitry” may refer to one or more or all of the following:
[0458] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and
[0459] (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
[0460] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0461] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0462] Embodiments herein may be implemented in software (executed by one or more processors), hardware (e.g., an application specific integrated circuit), or a combination ofsoftware and hardware. In an example embodiment, the software (e.g., application logic, an instruction set) is maintained on any one of various conventional computer-readable media. In the context of this document, a “computer-readable medium” may be any media or means that can contain, store, communicate, propagate or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer, with one example of a computer described and depicted, e.g., in FIG. 4. A computer-readable medium may comprise a computer-readable storage medium (e.g., memories 75 and 95 or other device) that may be any media or means that can contain, store, and / or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer. A computer-readable storage medium does not comprise propagating signals, and therefore may be considered to be non-transitory. The term “non-transitory”, as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM, random access memory, versus ROM, read-only memory).
[0463] If desired, the different functions discussed herein may be performed in a different order and / or concurrently with each other. Furthermore, if desired, one or more of the above-described functions may be optional or may be combined.
[0464] Although various aspects of the invention are set out in the independent claims, other aspects of the invention comprise other combinations of features from the described embodiments and / or the dependent claims with the features of the independent claims, and not solely the combinations explicitly set out in the claims.
[0465] It is also noted herein that while the above describes example embodiments of the invention, these descriptions should not be viewed in a limiting sense. Rather, there are several variations and modifications which may be made without departing from the scope of the present invention as defined in the appended claims.
[0466] The following abbreviations that may be found in the specification and / or the drawing figures are defined as follows:
[0467] 3 GPP third generation partnership project
[0468] 5G fifth generation
[0469] 5GC 5G core (network)
[0470] ACME Automated Certificate Management Environment
[0471] ALPN Application-Layer Protocol Negotiation
[0472] alt alternative
[0473] AMF access and mobility management function
[0474] CA certificate authority
[0475] CSR or csr certificate Signing Request
[0476] DNS or dns domain name server
[0477] E-SMLC evolved serving mobile location center
[0478] GMLC Gateway Mobile Location Center
[0479] eNB (or eNodeB) evolved Node B (e.g., an LTE base station)
[0480] gNB (or gNodeB) base station for 5G / NR
[0481] HTTP or http hyper-text transfer protocol
[0482] IETF Internet Engineering Task Force
[0483] I / F interface
[0484] IP or op internet protocol
[0485] LMF Location Management Function
[0486] LIE long term evolution
[0487] MAC Message Authentication Code
[0488] MME mobility management entity
[0489] NF 99 network function
[0490] NFc Network Function Consumer
[0491] NFp Network Function Producer
[0492] ng or NG next generation
[0493] NR new radio
[0494] NRF Network Repository Function
[0495] N / W or NW network
[0496] 0AM Operation, Administration, and Maintenance
[0497] PKI Public Key Infrastructure
[0498] RAN radio access network
[0499] RFC Request For Comment
[0500] Rx receiver
[0501] SAN Subject Alternative Name
[0502] SBA Service Based Architecture
[0503] SGW serving gateway
[0504] SID Study Item Description
[0505] SMF session management function
[0506] SSL secure sockets layer
[0507] TLS transport layer security
[0508] TRP transmission-reception point
[0509] Tx transmitter
[0510] UDM unified data management
[0511] UDR unified data repository
[0512] UE user equipment (e.g., a wireless, typically mobile device)
[0513] UPF user plane function
[0514] URL or URL uniform resource locator
Claims
CLAIMS:
1. An apparatus, comprising means for performing: receiving, at an automated certificate management environment server from a network element in a cellular network, a certificate signing request comprising indication of a domain and a subject alternative name comprising a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with the domain present in the certificate Signing Request; performing, by the automated certificate management environment server, a validation by validating the digital signature using the retrieved certificate for the operation, administration, and maintenance and validating that one or more parameters encoded in the digital signature match with corresponding one or more parameters from the certificate Signing Request; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validation.
2. The apparatus according to claim 1, wherein the means are further configured for performing: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the certificate signing request.
3. The apparatus according to any of claims 1 to 2, wherein: the means are further configured for performing determining, prior to receiving the certificate signing request, by the automated certificate management environment server that subject alternative name-based digital signature challenge is supported; andthe receiving comprises, based on the subject alternative name-based digital signature challenge being supported, examining the subject alternative name in the certificate signing request for the digital signature.
4. The apparatus according to any of claims 1 to 3, wherein the one or more parameters from the certificate signing request comprise one or more of NFInstancelD, NFType, or NFSlicelDlist.
5. An apparatus, comprising means for performing: generating, by an operation, administration, and maintenance in a core network of a cellular network, a digital signature using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for a network element that is in the cellular network; and communicating, by the operation, administration, and maintenance, at least the digital signature to the network element.
6. The apparatus according to claim 5, wherein the means are further configured for performing: communicating, by the operation, administration, and maintenance with an automated certificate management environment server, to configure the certificate for the operation, administration, and maintenance prior to generating the digital signature.
7. The apparatus according to any of claims 5 to 6, wherein the communicating, by the operation, administration, and maintenance, at least the digital signature to the network element comprises configuring, on the network element, a profile for the network element, the profile comprising the digital signature.
8. The apparatus according to claim 7, wherein the profile further comprises one or more parameters and the digital signature comprises the one or more parameters.
9. The apparatus according to any of claims 5 to 8, wherein: the means are further configured for performing: receiving, by the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the generating the digital signature is performed in response to the receiving the message; and the communicating, by the operation, administration, and maintenance, at least the digital signature to the network element comprises: sending, by the operation, administration, and maintenance to the network element, a message comprising the generated digital signature.
10. An apparatus, comprising means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for an operation, administration, and maintenance and using one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a certificate signing request comprising indication of a domain and a subject alternative name comprising the digital signature; and receiving, by the network element from the automated certificate management environment server and in response to the certificate Signing Request, a transport layer security / secure sockets layer certificate issued by the automated certificate management environment server.
11. The apparatus according to claim 10, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation,administration, and maintenance, of a profile for the network element, the profile comprising the digital signature and the one or more profile parameters for the network element.
12. The apparatus according to claim 10, wherein the means are further configured for performing: sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
13. An apparatus, comprising means for performing: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; validating, by the automated certificate management environment server, the digital signature using the retrieved certificate for the operation, administration, and maintenance and performing a validation of the plain identifier by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier from the first request; andissuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
14. The apparatus according to claim 13, wherein the means are further configured for performing: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the first request.
15. The apparatus according to any of claims 13 to 14, wherein: the means are further configured for performing determining, prior to receiving the first request, by the automated certificate management environment server that identifier based digital signature is supported for the domain; and the receiving the first request comprises, based on the identifier based digital signature being supported, examining the first request for the plain identifier.
16. An apparatus, comprising means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with a certificate for the operation, administration, and maintenance on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request comprising a plain identifier having a certain identifier type and used to identify an instance of the network element, and a digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; andreceiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
17. The apparatus according to claim 16, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature and the one or more profile parameters for the network element.
18. The apparatus according to claim 16, wherein: the means are further configured for performing: sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; and the receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
19. An apparatus, comprising means for performing: receiving, at an automated certificate management environment server from a network element in a cellular network, a first request as part of a certificate request procedure; retrieving, by the automated certificate management environment server, a certificate for an operation, administration, and maintenance that is associated with a domain present in the first request; sending, by the automated certificate management environment server to the network element, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; validating, by the automated certificate management environment server, a digital signature retrieved using the url and the certificate for the operation,administration, and maintenance, and performing a validation of a plain identifier, retrieved using the url and having a certain identifier type and used to identify an instance of the network element, by matching the plain identifier with an identifier encoded in the digital signature; receiving, by the automated certificate management environment server from the network element, a second request; validating, by the automated certificate management environment server, a plain identifier that is in the second request and that has the certain identifier type and is used to identify the instance of the network element matches with the plain identifier retrieved from the url; and issuing, by the automated certificate management environment server to the network element, a transport layer security / secure sockets layer certificate based on successful validating.
20. The apparatus according to claim 19, wherein the means are further configured for performing: configuring, by the automated certificate management environment server and to the operation, administration, and maintenance, the certificate for the operation, administration, and maintenance prior to receiving the first request.
21. The apparatus according to any of claims 19 to 20, wherein: the means are further configured for performing determining, prior to receiving the certificate signing request, by the automated certificate management environment server that a digital signal challenge type is supported for the domain; and the sending the response having the challenge type of the digital signature and having the url of the automated certificate management environment server is performed based on the digital signal challenge type being supported and the first request being received.
22. An apparatus, comprising means for performing: receiving, at a network element in a cellular network from an operation, administration, and maintenance in a core network of the cellular network, a digital signature that has been determined using a private key associated with an operation, administration, and maintenance certificate on one or more profile parameters for the network element; sending, by the network element to an automated certificate management environment server, a first request as part of a certificate request procedure; receiving, by the network element and from the automated certificate management environment server, a response having a challenge type of a digital signature and having an url of the automated certificate management environment server; writing, by the network element and to the automated certificate management environment server by using the url, a plain identifier having a certain identifier type and used to identify an instance of the network element, and the digital signature; sending, by the network element to the automated certificate management environment server, a second request comprising the plain identifier; and receiving, by the network element from the automated certificate management environment server and in response to the second request, an issued transport layer security / secure sockets layer certificate.
23. The apparatus according to claim 22, wherein the receiving the digital signature comprises receiving configuration, by the network element from the operation, administration, and maintenance, of a profile for the network element, the profile comprising the digital signature.
24. The apparatus according to claim 22, wherein: the means are further configured for performing sending, to the operation, administration, and maintenance from the network element, a message indicating the digital signature is to be generated; andthe receiving the digital signature comprises receiving, by the network element from the operation, administration, and maintenance, a message comprising the digital signature that was generated.
25. The apparatus according to any of apparatus claims 1 to 24, where the network element is a network function in the core network of the cellular network.
26. The apparatus of any preceding apparatus claim, wherein the means comprises: at least one processor; and at least one memory storing instructions that, when executed by at least one processor, cause the performance of the apparatus.