Methods for automated certificate management environment (ACME) certificate renewal in 5g service based architecture (SBA)

The ACME protocol addresses inefficiencies in 5G SBA networks by automating certificate renewal with AI/ML-driven proactive identification and reduced complexity, ensuring secure and timely certificate management in dynamic 5G networks.

WO2026073045A1PCT designated stage Publication Date: 2026-04-02GOOGLE LLC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing 5G networks face inefficiencies in certificate renewal processes due to client-initiated, manual or semi-automated workflows, which fail to align with dynamic operational conditions and often require repeated validation steps, leading to delays and computational overheads, especially in Service-Based Architecture (SBA) environments.

Method used

Implementing the Automatic Certificate Management Environment (ACME) protocol to automate certificate renewal processes, using triggering mechanisms between 5GC NFs and operator CAs, with AI/ML for proactive renewal identification and risk assessment, and integrating with 3GPP systems for flexibility and reduced complexity.

Benefits of technology

Ensures robust and automated management of security credentials, optimizing renewal timing and relevance, reducing unnecessary overhead, and maintaining secure connections in dynamic 5G networks by leveraging ACME's flexibility and automation capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025048312_02042026_PF_FP_ABST
    Figure US2025048312_02042026_PF_FP_ABST
Patent Text Reader

Abstract

A method can be implemented in a network function (NF) of a core network (CN) or in a certificate authority (CA), for renewing an Automated Certificate Management Environment (ACME) certificate. The method can include receiving or providing an ACME certificate. The method can include transmitting or receiving a request, in response to a trigger event and in accordance with a configuration for the trigger event, related to renewal of the security certificate. The method can include receiving or providing a renewed security certificate in response to the request. Other methods and apparatuses are described.
Need to check novelty before this filing date? Find Prior Art

Description

PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 METHODS FOR AUTOMATED CERTIFICATE MANAGEMENT ENVIRONMENT (ACME) CERTIFICATE RENEWAL IN 5G SERVICE BASED ARCHITECTURE (SBA) CROSS-REFERENCE TO RELATED APPLICATION

[0001] This application claims priority to and the benefit of the filing date of provisional U.S. Patent Application No.63 / 669,770, entitled “Methods for Automated Certificate Management Environment (ACME) certificate renewal in 5G Service Based Architecture (SBA),” filed on September 26, 2024. The entire content of the provisional application is hereby expressly incorporated herein by reference. FIELD OF THE DISCLOSURE

[0002] This disclosure relates generally to network security in a wireless network and, more particularly, to certificate enrollment, issuance, and renewal. BACKGROUND

[0003] This background description is provided for the purpose of generally presenting the context of the disclosure. Work of the presently named inventors, to the extent it is described in this background section, as well as aspects of the description that may not otherwise qualify as prior art at the time of filing, are neither expressly nor impliedly admitted as prior art against the present disclosure.

[0004] Currently, 5G networks provide certificate management within Service-Based Architecture (SBA) environments that often require periodic renewal of digital security certificates to maintain secure communication channels. Existing processes for certificate renewal are predominantly client-initiated and rely on manual or semi-automated workflows, which may not align well with dynamic operational conditions such as certificate expiration due to preconfigured times or unforeseen security vulnerabilities. Additionally, client-initiated systems occasionally lack mechanisms to efficiently detect renewal conditions, causing delays and disruptions in maintaining secure connections within network functions.

[0005] Another challenge in conventional approaches involves handling authorization challenges during the renewal process. For instance, Certificate Authority / Registration AuthorityPATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 (CA / RA) servers may repeatedly request validation responses from the client, introducing inefficiencies and potential failure points when renewal procedures cannot be completed within constrained time intervals. Further complicating the process, servers are often unable to pre- authorize trusted clients for streamlined certificate issuance, forcing repeated validation steps regardless of prior success, resulting in unnecessary complexity and increased computational loads.

[0006] To address these and other concerns, some systems may use the Certificate Management Protocol (CMP) to obtain digital certificates in a public key infrastructure (PKI). CMP has proven to be well-suited for environments with private CAs and integration with internal systems. However, CMP is relatively complex. In contrast, the Automatic Certificate Management Environment (ACME) protocol is generally simpler to implement. ACME can integrate with public CAs, and operators can adapt ACME with private CAs as well.

[0007] However, it is unclear how to align certificate procedures, such as renewal and revocation procedures within the ACME protocol in a 5G Core (5GC) Service-Based Architecture (SBA). SUMMARY

[0008] An example embodiment of the techniques of this disclosure is a method implemented in a first network function (NF) of a core network (CN), the method comprising: receiving, from a certificate authority (CA), a security certificate and a configuration that defines conditions for a trigger event, the conditions being based on policy configurations for certificate renewal; transmitting to the CA, in response to the trigger event, a request related to renewal of the security certificate; and receiving a renewed security certificate in response to the request.

[0009] Another example embodiment of the techniques of this disclosure is a method implemented in a certificate authority (CA), the method comprising: transmitting, to a first network function (NF) of a core network (CN), a security certificate and a configuration that defines conditions for a trigger event, the conditions being based on policy configurations for certificate renewal; receiving, from the first NF, in accordance with the configuration for the trigger event, a request related to renewal of the security certificate; and transmitting a renewed security certificate in response to the request.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0010] Yet another example embodiment of these techniques is a network device. The network device comprises a transceiver processing hardware configured to implement a method of one of the methods above. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Fig.1 is a block diagram of an example wireless communication system, such as a 5G system (5GS), that supports renewal of security certificates;

[0012] Fig.2 is a service-based representation of the 5GS architecture;

[0013] Fig.3 is a reference-point based representation of the 5GS architecture, including overall non-roaming reference architecture of the policy and charging control framework for the 5GS;

[0014] Fig.4 is a high-level messaging diagram of a client-initiated certificate renewal request process;

[0015] Fig.5 is a high-level messaging diagram of a client-initiated certificate renewal request process with pre-authorization;

[0016] Fig.6 is a high-level messaging diagram of a server-initiated certificate renewal process;

[0017] Fig.7 is a high-level messaging diagram of a server-initiated certificate renewal process with pre-authorization; and

[0018] Fig.8 is a flow diagram of an example method for certificate renewal, which can be implemented in a network function (NF); and

[0019] Fig.9 is a flow diagram of an example method for certificate renewal, which can be implemented in a certificate authority (CA).

[0020] Fig.10 is a flow diagram of a second example method for certificate renewal, which can be implemented in an NF; and

[0021] Fig.11 is a flow diagram of a second example method for certificate renewal, which can be implemented in a CA.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 DETAILED DESCRIPTION OF THE DRAWINGS Overview

[0022] The disclosed technology provides systems and methods for managing security certificates in Service-Based Architecture (SBA) networks, particularly those used in 5G networks, through the Automatic Certificate Management Environment (ACME) protocol. These systems and methods address processes such as certificate renewal, ensuring robust and automated management of security credentials within the dynamic architecture of modern telecommunications networks. The ACME-based approach facilitates secure certificate lifecycle management for network functions (NFs) operating as ACME clients, interacting with certificate authorities / registration authorities (CA / RA) designed as ACME servers.

[0023] According to other aspects of the present disclosure, legacy systems can integrate with ACME workflows and account for varying levels of network security and computational capability. For instance, where high-security requirements are in place, the disclosed workflows allow extensive validation mechanisms for certificate issuance. Conversely, in low-security environments, simplified workflows such as pre-authorizations and short-lived certificates ensure adaptable solutions that reduce unnecessary overhead.

[0024] According to still other aspects, systems described herein apply artificial intelligence or machine learning (AI / ML) to identify conditions for renewal proactively or to assess risk levels for specific certificates. By leveraging data-driven insights, the ACME-enabled workflows can optimize timing and relevance of renewal requests, ensuring that certificates remain secure and appropriately managed even as network conditions evolve.

[0025] Devices can use the Certificate Management Protocol (CMP) to obtain digital certificates in a public key infrastructure (PKI). A vendor can pre-provision devices (e.g., UEs, base stations, network functions (NFs)) with a public-private key pair, and the device can have the vendor-signed certificate of the device public key pre-installed. A Registration Authority (RA) or Certificate Authority (CA) can operate as a Certificate Management Protocol (CMP) server. CMP can provide certificate lifecycle management capabilities for secure gateways (SEGs) and network entities (NEs).PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0026] CMP is suited for environments with private CAs and integration with internal systems. However, CMP is complex to implement. Further, while CMP is integrated with 3GPP to some extent, more advanced, flexible systems may provide integration of ACME with 3GPP systems.

[0027] The ACME protocol provides flexibility and the opportunity to automate certain aspects of certificate management, in addition to providing reduced complexity. Furthermore, ACME certificate management provides desired focus on web services and automated (e.g., “scriptable”) behavior. ACME may be particularly well suited in infrastructure deployment use cases, including deployment of network functions (NFs) on cloud native platforms (e.g., Kubernetes), which have built-in support for ACME. ACME also reduces the complexity by automating the validation of authority, which can be particularly helpful in multi-vendor environments.

[0028] To better use ACME in a service-based architecture, systems and methods may implement a certificate renewal mechanism. As discussed in more detail below, according to a certain approach, systems can initiate certificate renewal using triggering mechanisms between 5GC NFs and operator CAs. Certain aspects of certificate renewal may address key issues (KIs) defined in 3GPP TRS 33.776 (“Study of ACME for Automated Certificate Management in SBA”). Based on various policies and conditions, a CA / RA server may renew 5G NF (or ACME client) security certificates based on the ACME protocol as defined in IETF RFC 8555: “Automatic Certificate Management Environment (ACME).” Example system

[0029] Referring first to Fig.1, an example wireless communication system 100 can implement one or more of the techniques of this disclosure for supporting renewal of security certificates. The example wireless communication system 100 includes a UE 102, a base station (BS) 104, a base station 106, and a core network (CN) 110. The CN 110 may be or include an evolved packet core (EPC) 111, a fifth generation (5G) core (5GC) 160, and / or a sixth generation (6G) core (6GC) 170, for example. Any of the base stations 104, 106 can be an eNB supporting an S1 interface for communicating with the EPC 111, an ng-eNB supporting an NG interface for communicating with the 5GC 160, or a gNB that supports an NR radio interface as well as an NG interface for communicating with the 5GC 160. Any of the base stations 104, 106 can alsoPATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 be an 6G base station (BS) supporting the NG interface, a new NG interface, or a 6G BS-to-CN (e.g., N6G) interface for communicating with the 5GC 160 or the 6GC 170. To directly exchange messages with each other during the scenarios discussed below, the base stations 104, 106 can support an X2, Xn, new Xn, or 6G BS-to-BS (e.g., X6G) interface. Among other components, the EPC 111 can include a Serving Gateway (SGW) 112, a Mobility Management Entity (MME) 114, and a Packet Data Network Gateway (PGW) 116. The SGW 112 is generally configured to transfer user-plane packets related to audio calls, video calls, Internet traffic, etc., and the MME 114 is configured to manage authentication, registration, paging, and other related functions. The PGW 116 provides connectivity from the UE to one or more external packet data networks, e.g., an Internet network and / or an Internet Protocol (IP) Multimedia Subsystem (IMS) network. The 5GC 160 includes a User Plane Function (UPF) 162 and an Access and Mobility Management (AMF) 164, and / or a Session Management Function (SMF) 166. The UPF 162 is generally configured to transfer user-plane packets related to audio calls, video calls, Internet traffic, etc., the AMF 164 is configured to manage authentication, registration, paging, and other related functions, and the SMF 166 is configured to manage PDU sessions. The 6GC 170 includes a 6G UPF 172 and a 6G AMF 174, and / or 6G SMF 176, similar to the UPF 162, the AMF 164 and the SMF 176 with enhanced functions, respectively.

[0030] As illustrated in Fig.1, the base station 104 supports cell 124, and cell 125, and the base station 106 supports cells 126. The cells 124, 125, and 126 can partially overlap to provide seamless service continuity. Thus, while the UE 102 may move among the cells 124, 125, and 126, the UE 102 still communicate with the CN 110 via these cells. In general, the wireless communication system 100 can include any suitable number of base stations supporting 6G cells, NR cells and / or EUTRA cells. More particularly, the EPC 111 can be connected to any suitable number of base stations supporting EUTRA cells, while the 5GC 160 and / or the 6GC 170 can be connected to any suitable number of base stations supporting 6G cells and / or NR cells. Although the examples below refer specifically to specific CN types (EPC, 5GC, 6GC) and RAT types (6G, 5G NR and EUTRA), in general the techniques of this disclosure also can apply to other suitable radio access and / or core network technologies such as seventh generation (7G) radio access and / or 7G core network.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0031] Several NFs that make up the CN 110 are discussed below with reference to Figs.2 and 3. One or more of the NFs of the CN 110 can act as an ACME client 192 to interact with an ACME server 194 (e.g., a CA) according to methods described with reference to Figs.4-8. Any suitable network function (NF) described with reference to Fig.2 or Fig.3 can implement the ACME client 192. For example, ACME client 192 can comprise a 5G cloud-native network function (CNF), although embodiments are not limited thereto.

[0032] While not shown in Fig.1 to avoid clutter, the CN 110 may include processing hardware, which may include one or more general-purpose processors (e.g., CPUs) and a non- transitory computer-readable memory storing instructions that the one or more general-purpose processors execute. Additionally or alternatively, the processing hardware can include special- purpose processing units. The processing hardware may be configured to implement the techniques of this disclosure for enabling 5GS support for certificate issuance, enrollment, and renewal according to ACME protocols or other certificate management protocols (e.g., CMP).

[0033] While not shown in Fig.1 to avoid clutter, the base stations 104 and 106 and the UE 102 are equipped with one or more processors that can include one or more general-purpose processors (e.g., CPUs) and a non-transitory computer-readable memory storing instructions that the one or more general-purpose processors execute (not shown). Additionally or alternatively, the processing hardware can include special-purpose processing units. Fig.2 is a service-based representation 200 of the 5GS architecture, which the system of Fig.1 can implement. In the service-based representation 200, the overall non-roaming reference architecture of the policy and charging control (PCC) framework for the 5GS includes components illustrated using solid lines, and the other components are illustrated using dashed lines. According to this representation, network functions enable other authorized network functions to access their services. The components that are outside the PCC framework include a Network Slicing Selection Function (NSSF) 202, a Network Repository Function (NRF) 206, a Unified Data Management (UDM) 208, an Edge Application Server Discovery Function (EASDF) 210, a Network Slice Specific Authentication and Authorization Function (NSAAF) 212, an Authentication Server Function (AUSF) 214, a Service Communication Proxy (SCP) 216, and a Network Slice Admission Control Function (NSACF) 218. The non-PCC architecture furtherPATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 includes the UE 102, the RAN 105, and a data network (DN) 230. An application server (AS) 231 operates in the DN 230.

[0034] The PCC framework in the service-based representation 200 includes a Unified Data Repository (UDR) 252, a Network Exposure Function (NEF) 254, a network data analytics function (NWDAF) 256, an Application Function (AF) 258, a Policy Control Function (PCF) 260, a Charging Function (CHF) 262, an Access & Mobility Management Function (AMF) 264, a Session Management Function (SMF) 266, and a User Plane Function (UPF) 270.

[0035] In an example implementation, an ACME server 194 runs at a CA / RA and responds to ACME client requests according to methods described later herein with reference to Figs.4-9.

[0036] Fig.3 is a reference-point based representation 300 of the 5GS architecture. In Fig.3, the non-roaming reference architecture of the PCC framework for the 5GS is illustrated as blocks and connections with solid lines, and components and connections outside the PCC framework are illustrated using dashed lines.

[0037] Next, several example scenarios for a certificate renewal process are described with reference to Figs.4-9. A certificate renewal in the context of 5G SBA with ACME may be defined as issuance of a new certificate to replace the old certificate. Renewal solutions can be initiated by either an ACME client or an ACME server, according to methods described with reference to Figs.4-9 and renewal solutions can use similar call flows regardless of whether the renewal is client- or server-initiated.

[0038] Generally speaking, events in Figs.4-9 that are similar are labeled with similar reference numbers with similar two least significant digits (e.g., event 402 of Fig.4 is similar to event 502 of Fig.5, event 602 of Fig.6, and event 702 of Fig.7), with differences discussed below where appropriate. With the exception of the differences shown in the figures and discussed below, any of the alternative implementations discussed with respect to a particular event (e.g., for messaging and processing) may apply to events labeled with similar reference numbers in other figures.

[0039] Fig.4 is a high-level messaging diagram 400 of a client-initiated certificate renewal request process. More particularly, the process of Fig.4 is client-initiated and automated ("scripted"). Some of the events in Fig.4 can involve both automated and manual steps. ForPATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 example, a trigger as in event 406 can include manual input, whereas the operations that follow the trigger 406 can be fully automated and not involve any manual input.

[0040] The messaging diagram 400 illustrates example messaging between an ACME client 192, which can be implemented in a 5G NF, and an ACME server 194, which operates as an CA / RA. The ACME client 192 downloads 402 a certificate after a successful certificate enrollment (issuance) procedure or process. In some example embodiments, the ACME client 192 completes certification enrolment (issuance) process and receives a signed certificate from the appropriate CA / RA (e.g., the ACME server 194) as described in, e.g., Solution #5 of TR 33.776.

[0041] The ACME client 192 receives 404 a configuration including certificate renewal policies and conditions. It general, operators do not send certificate renewal policies (alternatively referred to as policies, conditions, or constraints) over the air (i.e., not directly between the ACME server and ACME client). In some examples, an operator programs the policies / conditions into the Core Network Function. Additionally, the operator can configure the ACME client 192 to poll for the latest event / conditions or receive a trigger based on certain conditions such as the following examples (although embodiments are not limited thereto). First, the ACME client 192 in the CN 110 may have a certificate expiration time configured by the ACME server 194, another suitable CA / RA, or a threat-detection core network function. Such a trigger may be activated when the certificate is nearing expiration (e.g., after ⅔ of certificate validity time has passed) or has expired. As a second example condition, the certificate renewal may be triggered if a 5G NF detects that the certificate has been compromised or is highly risky based on artificial intelligence (AI) or machine learning (ML) prediction and / or data analysis recommendation.

[0042] In a third example condition, the threat-detection core network function may detect a compromise of the private key, which can send a trigger to the 5G NF. As a fourth example condition, the threat-detection core network function system may have a configuration such that the threat-detection core network function may trigger a request for a certificate renewal for the 5G NF when, for example, the threat-detection core network function initiates a software update. As a fifth example condition, the threat-detection core network function may trigger certificate renewal when there is a change of organization information. The conditions describedPATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 here benefit short-lived certificates in the ACME protocol for 5G SBA, and conditions are not limited to the conditions listed herein.

[0043] With continued reference to Fig.4, the ACME client 192 detects or receives 406 a trigger for certificate renewal based on the conditions pre-configured in the 5GC as described with respect to operation 404.

[0044] Based on the received trigger, the ACME client 192 initiates 408 a request for certificate renewal to the ACME server 194. The request the ACME client 192 transmits 408 can include an indication of the trigger (cause value). This indication, as discussed in more detail below, may be useful for ML for training threat detection or even more automated certificate renewals.

[0045] The ACME server 194 transmits 410, to the ACME client 192 and in response to the request 408, an indication (e.g., 201 ‘Created’) that the request has been fulfilled, with further actions to be performed by the ACME client 192. In addition, the ACME server 194 transmits an authorization challenge / s, to which the ACME client 192 can respond.

[0046] The ACME client 192 checks 412 the authorization challenge and completes the listed challenges. In addition, the ACME client 192 sends 413 a Certificate Signing Request (CSR) to the ACME server 194. In a CMP embodiment, in contrast to automated ACME methods, operation 410 would be manually triggered by a CMP server (e.g., a CA / RA), and operation 412 would be the result of that manual triggering. The ACME client 192 can send 413, to a the ACME server 194, the challenge validation information and the CSR.

[0047] If the ACME server 194 determines 414 that the challenge validation outcome the ACME client 192 provided 412 is not completed successfully or is incomplete, the ACME server 194 re-sends 414 an authorization challenge to the ACME Client 192. This procedure can also be referred to as a challenge failure fallback, which can be performed automatically. The number of repeats can be automated or scripted.

[0048] If the challenge is not completed successfully prior to the expiration time the ACME server 194 provided initially or in an update, the ACME client 192 may start 416 a wait timer and resend the certificate renewal request as described in operation 408, restarting the renewal request. The wait timer may be pre-configured with an appropriate wait time (e.g., zero seconds).PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 The operation 416 can be performed in an automated fashion. Eventually, if the challenge is not completed successfully prior to the expiration time the ACME server 194 provided initially or in an update, the ACME server 194 can drop the order.

[0049] When the ACME client 192 successfully completes the challenge validation procedure, the ACME server 194) can generate 417 a certificate for the ACME client 192 and send 418 an acknowledgment. If the challenge response is valid, the ACME server 194 can issue the certificate and publish the certificate for the ACME client 192 to download.

[0050] The ACME client 192 downloads 420 the certificate, for example, by sending a POST- as-GET request to the trusted URL.

[0051] Fig.5 is a high-level messaging diagram 500 of a client-initiated certificate renewal request process with pre-authorization. More particularly, the process of Fig.5 includes messaging between an ACME client 192 and an ACME server 194 similar to that of the messaging diagram 400. Therefore, the description of Fig.5 omits description of operations that are similar to the messaging diagram 400.

[0052] The ACME server 194 pre-authorizes 522 a list of ACME clients 192 for certificate renewal.

[0053] In operation 524, upon receiving the certificate renewal request, The ACME server 194 checks 524 upon receiving 508 a certificate renewal request, whether the ACME client 192 is pre-authorized for certificate renewal. Upon identifying that the ACME client 192 is pre- authorized for certificate renewal the ACME server 194 transmits 526 sends an acknowledgement and indication to the ACME client 192 that no authorization challenge is required. If, however, the ACME client 192 is not pre-authorized then the ACME server 194 sends an authorization challenge to the ACME Client 192. In some example embodiments, a time limit (e.g., time interval) may limit pre-authorization. For example, the ACME client 192 may keep track of a time interval. If the renewal request is outside of the time-interval, then the ACME server 194 sends an authorization challenge to the ACME client 192. For example, if the renewal interval constraint is one week (336 hours) and if an ACME client 192 sends a renewal request after 336 hours of the last certificate issuance, then the ACME server 194 may send an authorization challenge request to the ACME client 192.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0054] Based on the response / indication received, the ACME client 192 sends 528 a Certificate Signing Request to the ACME server 194. The ACME server 194 can send 518 an acknowledgment and receive 520 a request for certificate download.

[0055] In an evaluation procedure (addressing KI#5 defined in TR 33.776), pre-defined certificate renewal policies and conditions in the ACME client 192 trigger the process for certificate renewal. An ACME client 192 sends the certificate renewal request to a trusted ACME server 194. The ACME server 194 sends challenge validation objects to the ACME client 192, which the ACME client 192 needs to complete successfully. The ACME server 194 may resend a challenge validation request to the ACME client 192 if the previous challenge was unsuccessful. If the ACME client 192 could not complete the challenge validation procedure within an expiration time initially provided by the ACME server 194, then the ACME client 192 may restart the certificate renewal process. The ACME client 192 sends a certificate signing request along with a challenge response to the ACME server 194. The ACME server 194 issues, to the 5G NF, a signed certificate upon a successful challenge response.

[0056] An ACME server 194 may pre-authorize an ACME client 192certificate renewals. In such a scenario, the ACME server 194 may not involve challenge validation steps. However, the time-interval (within which the ACME server 194 expects to receive a certificate renewal request for the ACME server 194 to issue a certificate without challenging the client) may constrain this pre-authorization.

[0057] Fig.6 is a high-level messaging diagram 600 of a server-initiated certificate renewal request process. The messaging diagram 600 illustrates messaging between an ACME client 192 an ACME server 194 similar to that of the messaging diagrams 400 and description of similar operations is omitted with only differences in operation being noted. The solution illustrated in Fig.6 addresses KI#5 (as defined in TR 33.776). A certificate renewal in the context of 5G SBA with ACME may be defined as issuance of a new certificate to replace the old certificate. This solution uses similar call flows as client-initiated ACME-based certificate renewal procedure. However, unlike client-initiated ACME-based certificate renewal as described in RFC 8555, this solution proposes a server-initiated ACME certificate renewal procedure.

[0058] The ACME server 194 pre-configures 604 certificate renewal policies and conditions. The conditions may be part of the renewal policies. The certificate renewal may be initiatedPATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 based on these policies and conditions, for instance: time for renewal (e.g., 11:59 PM EST); remaining valid-time for an issued certificate (e.g., 2 / 3rd of the valid time); AI / ML prediction and data analysis recommendation trigger; security vulnerability or risk condition trigger; and / or scheduled renewal period (e.g., Short-lived certificate). These conditions are examples and embodiments are not limited thereto. The ACME server 194 keeps track of these conditions for an ACME client 192 or a set of clients. Furthermore, certificate renewal may be constrained with conditions. For example: a renewal window (e.g., between 12:00 AM July 1, 2025 - July 31, 2025); and / or an area or segment for renewal (e.g., sector A, geographical region B, 5G Core #5, etc.). These conditions are examples and embodiments are not limited thereto.

[0059] Provided that a certificate renewal condition has been met, the ACME server 194 receives 606 a trigger to initiate a certificate renewal procedure. The ACME server 194 may create a resource for certificate renewal (for the ACME client 192 to download) for intended ACME clients 192 considering a certificate was issued previously.

[0060] Based on the trigger received, the ACME server 194 sends 630 an indication for certificate renewal. In addition to this indication message, the ACME server 194 sends an authorization challenge. Furthermore, the ACME server 194 may send an indication for a resource created (e.g., 201 ‘created’) to inform that a renewed certificate is being issued and the ACME client 192 should respond to the authorization challenge successfully.

[0061] The ACME client 192 checks the indication from ACME server 194 and identifies that the ACME client 192 needs to renew the certificate. The ACME client 192 then checks the authorization objects to complete the listed challenges. The ACME client 192 completes the challenges and sends the response to the ACME server 194 with Certificate Signing Request (CSR).

[0062] If the ACME client 192 successfully completes the authorization challenge, the ACME server 194 will issue 634 the certificate and publish the certificate in the corresponding resource directory.

[0063] If the response from the ACME client 192 indicates that the authorization challenge was not completed successfully, the ACME server 194 sends 614 an indication informing of a failure and a new authorization challenge request.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0064] Eventually, if the authorization challenge is not completed successfully prior to the expiration time initially provided by the ACME server 194 or updated by the ACME server 194, the order will be dropped by the ACME server 194.

[0065] Provided that the authorization challenge is completed successfully, the ACME server 194 generates 636 the certificate and sends an acknowledgement to the ACME client 192 to inform the ACME client 192 about the certificate.

[0066] The ACME client 192 downloads 620 the certificate using a POST-as-GET Request.

[0067] Fig.7 is a high-level messaging diagram 700 of a server-initiated certificate renewal request process with pre-authorization. The messaging diagram 700 illustrates messaging between an ACME client 192 an ACME server 194 similar to that of the messaging diagrams 400 and 600 and description of similar operations is omitted with only differences in operation being noted.

[0068] The ACME server 194 pre-authorizes 522 a list of ACME clients 192 for certificate renewal. The list contains the ACME client 192 identifiers and corresponding security certificates identifiers.

[0069] The CA / RA (ACME server 194) is pre-configured 706 (similarly to 406) with policies and conditions for certificate renewal. The ACME server 194 receives a certificate renewal trigger based on the policies and conditions described with reference to operation 404.

[0070] The ACME server 194 sends 739 an indication (e.g., 201 Created message) to the ACME client 192 based on the trigger received, informing that a renewed certificate is being issued. In addition, the ACME server 194 may send 740 a ‘pre-authorized’ indicator or indication that the ACME client 192 is pre-authorized for certificate renewal and that therefore the ACME client 192 need not perform an authorization challenge. Furthermore, the ACME server 194 may send 741 resource information (a trusted URL) for the ACME client 192 to download the signed certificate.

[0071] The ACME client 192 checks 742 the message received, identifies the certificate renewal request from the CA / RA (ACME server 194), and identifies the ‘pre-authorized’ indicator to learn that no authorization challenge needs to be validated. ACME client 192 thenPATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 sends a request towards the trusted URL to download the signed certificate (e.g., POST-as-GET Request).

[0072] Note that pre-authorization may be time limited (e.g., according to a time interval). For example, the ACME server 194 may keep track of a time interval. If the renewal request is outside of the time-interval, then the ACME server 194 sends an authorization challenge to the ACME client 192. For example, if the renewal interval constraint is set as a week (336 hours) and if an ACME client 192 sends a renewal request after 336 hours of the last certificate issuance, the ACME server 194 may send a challenge validation request to the 5G NF.

[0073] In an evaluation procedure (addressing KI#5 defined in TR 33.776), pre-defined certificate renewal policies and conditions in the ACME server trigger the process for certificate renewal. The ACME server sends the certificate renewal request to an ACME client. The ACME server sends challenge objects to the ACME client which the ACME client needs to complete successfully. The ACME server may resend a challenge validation request to the ACME client if the previous challenge was unsuccessful. Upon receiving a renewal request, the ACME client completes the challenge and sends a resulting response along with a certificate signing request to the ACME server. The ACME server issues, to the 5G NF, a signed certificate.

[0074] An ACME server may pre-authorize an ACME client for certificate renewals. In such a scenario, the ACME server may not involve challenge validation steps. However, the time- interval within which the ACME server expects to receive a certificate renewal request for it to issue a certificate without challenging the client may constrain this pre-authorization.

[0075] Fig.8 is a flow diagram of an example method 800 for certificate renewal. The ACME client 192 may implement method 800.

[0076] The method 800 can begin with operation 802 with the ACME client 192 receiving, from an ACME server 194, a security certificate (e.g., event 402, 502, 602, or 702).

[0077] The method 800 can continue with the ACME client 192 transmitting 808, to the CA (e.g., ACME server 194), in response to a trigger event and in accordance with a configuration for the trigger event, a request related to renewal of the security certificate (e.g., event 408 or 508). The configuration for the trigger event can indicate a condition for requesting the renewal of the security certificate and the method 800 can further include detecting the condition at thePATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 NF (e.g., event 406). The method 800 can include the ACME client 192 receiving, from the ACME server 194, the configuration.

[0078] The trigger event can include a command from the ACME server 194 to request the renewal of the security certificate. The configuration for the trigger event can configure the ACME client 192 to receive the command from the ACME server 194 (e.g., event 630 or 740).

[0079] The method 800 can continue with receiving 818 a renewed security certificate in response to the request (e.g., event 418 or 518).

[0080] The method 800 can include the ACME client 192 receiving an indication of whether an authorization challenge is required to implement the request (e.g., event 410, 526, or 630). The method 800 can include the ACME client 192 performing the authorization challenge if the indication indicates that the authorization challenge is required (e.g., event 412). The method 800 can include the ACME client 192 repeating the authorization challenge up to a threshold number of times until successful completion of the authorization challenge (e.g., event 414 or 614). The ACME client 192 can repeat the authorization challenge until a timeout occurs or until successful completion of the authorization challenge (e.g., event 416).

[0081] The method 800 can include the ACME client 192 receiving the renewed certificate comprises receiving an ACME message indicating that a resource is created (e.g., event 636). The method 800 can include, after transmitting the request, transmitting a Certificate Signing Request (CSR) to the ACME server 194 to request that the ACME server 194 sign the renewed security certificate; and receiving a signed renewed security certificate in response to the transmitting of the CSR (e.g., events 528 and 518). The method 800 can include the ACME client 192 transmitting a request to download the renewed certificate (e.g., event 420, 520, and 620).

[0082] Fig.9 is a flow diagram of an example method 900 for certificate renewal, which can be implemented in an ACME server 194.

[0083] The method 900 can begin with the ACME server 194 transmitting 902, to an ACME client 192, a security certificate (e.g., event 402, 502, 602, or 702).

[0084] The method 900 can continue with the ACME server 194 receiving 908, from the ACME client 192, in response to a trigger event and in accordance with a configuration for thePATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 trigger event, a request related to renewal of the security certificate (e.g., event 406, 408, 506, 508, 606, 632, 706 and 742). The method 900 can include providing the configuration for the trigger event to the ACME client 192 (e.g., event 404 or 604). The method 900 can include receiving the request from the NF (e.g., ACME client 192) based on the configuration (e.g., event 408 or 508).

[0085] The method 900 can continue with operation 918 with the ACME server 194 transmitting a renewed security certificate in response to the request (e.g., event 418 or 518).

[0086] The method 900 can include receiving a notification that the request will be transmitted by a second NF of the CN, the second NF being configured to implement threat detection functionality in the CN. The method 900 can include transmitting to the first NF, upon detecting the condition, an indication that a renewed certificate is being issued (e.g., event 630).

[0087] The method 900 can include transmitting, to the ACME client 192, an indication of whether an authorization challenge is required before renewal of the security certificate (e.g., event 410). The method 900 can include accessing a list of automatic certificate management environment (ACME) clients that are pre-authorized for certificate renewal (e.g., event 722). The method 900 can include transmitting the authorization challenge if the ACME client 192 is not found on the list (e.g., event 524). The method 900 can include transmitting a notification that the authorization challenge is not required otherwise (e.g., event 526).

[0088] The method 900 can include repeating the authorization challenge up to a threshold number of times until successful completion of the authorization challenge. The authorization challenge can alternatively or additionally be repeated until a timeout occurs or until successful completion of the authorization challenge.

[0089] The method 900 can include receiving, in the request, an indication of a reason for the request. The ACME server 194 can provide the reason as training data to a machine learning model implemented in a data analysis NF. The method 900 can include the ACME server 194 obtaining other training data including reasons for certificate action requests, and vulnerability levels of historical security certificates. This and other training data can be provided to the data analysis NF to train the machine learning model to predict a vulnerability level of a new security certificate based on reasons for certificate action requests associated with the new securityPATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 certificate. The method 900 can include the ACME server 194 or other device, NF, machine, etc., receiving a request to trigger certificate renewal based on the predicted vulnerability level.

[0090] Fig.10 is a flow diagram of a second example method 1000 for certificate renewal, which can be implemented in an NF or ACME client 192.

[0091] The method 1000 can begin with the ACME client 192 receiving 1004, from an ACME server 194, a security certificate and a configuration that defines conditions for a trigger event, the conditions being based on policy configurations for certificate renewal (e.g., event 402, 404, 502, 602, or 702). The conditions can include an expiration time of the security certificate. The conditions may be based on a detection that the security certificate has been compromised. The conditions include a prediction that the security certificate has a risk level above a threshold

[0092] The method 1000 can continue with the ACME client 192 transmitting 1008 to the ACME server 194, in response to a trigger event and in accordance with a configuration for the trigger event, a request related to renewal of the security certificate (e.g., event 408 or 508).

[0093] The method 1000 can continue with the ACME client 192 receiving 1018, from the ACME server 194, a renewed security certificate in response to the request (e.g., event 418 or 518).

[0094] The method 1000 can include the ACME client 192 receiving an indication of whether an authorization challenge is required to implement the request (e.g., event 410, 526, or 630). The method 1000 can include the ACME client 192 refraining from performing an authorization challenge if the renewed security certificate is not required for NF operations. The method 1000 can include the ACME client 192 implementing an ACME protocol.

[0095] Fig.11 is a flow diagram of a second example method 1100 for certificate renewal, which can be implemented in an ACME server 194.

[0096] The method 1100 can begin with the ACME server 194 transmitting 1102, to an ACME client 192, a security certificate and a configuration that defines conditions for a trigger event, the conditions being based on policy configurations for certificate renewal (e.g., event 402, 406, 502, 602, or 702). The configuration may include a certificate expiration time defined by the CA.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0097] The method 1100 can continue with the ACME server 194 receiving 1108, from the first NF, in accordance with the configuration for the trigger event, a request related to renewal of the security certificate (e.g., event 406, 408, 506, 508, 606, 632, 706 and 742).

[0098] The method 1100 can continue with the ACME server 194 transmitting 1118 a renewed security certificate in response to the request (e.g., event 418 or 518). The method 1100 can include

[0099] The method 1100 can include receiving a notification that the request will be transmitted by a second NF of the CN, the second NF being configured to implement threat detection functionality in the CN. The method 1100 can include refraining from transmitting the renewed certificate if the first NF is associated with a geographical region outside an authorized geographical region or if the first NF is associated with a computer domain outside an authorized computer domain.

[0100] The method 1100 can include accessing a list of ACME clients that are pre-authorized for certificate renewal, transmitting an authorization challenge if the first NF is not found on the list, and transmitting a notification that the authorization challenge is not required otherwise. The method 1100 can include repeating the authorization challenge up to a threshold number of times until successful completion of the authorization challenge.

[0101] The method 1100 can include obtaining training data including reasons for certificate action requests, and vulnerability levels of historical security certificates; providing the training data to a data analysis NF to train a machine learning model to predict a vulnerability level of a new security certificate based on reasons for certificate action requests associated with the new security certificate; and receiving a request to trigger certificate renewal based on the predicted vulnerability level. Additional Examples

[0102] The following list of examples reflects a variety of the embodiments explicitly contemplated by the present disclosure.

[0103] In Example 1, a method implemented in a first network function (NF) of a core network (CN) can comprise receiving, from a certificate authority (CA), a security certificate;PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 transmitting to the CA, in response to a trigger event and in accordance with a configuration for the trigger event, a request related to renewal of the security certificate; and receiving a renewed security certificate in response to the request.

[0104] In Example 2, the subject matter of Example 1 can further include wherein the configuration for the trigger event indicates a condition for requesting the renewal of the security certificate; the method further comprising: detecting the condition at the first NF.

[0105] In Example 3, the subject matter of Example 2 can further include receiving the configuration from the CA.

[0106] In Example 4, the subject matter of Example 1 can further include wherein the trigger event includes a command from the CA to request the renewal of the security certificate; and the configuration for the trigger event configures the first NF to receive the command from the CA.

[0107] In Example 5, the subject matter of any of the preceding Examples can further comprise storing the configuration from the CA.

[0108] In Example 6, the subject matter of any of the preceding Examples can further comprise wherein the condition for requesting the renewal is based on an expiration time of the security certificate.

[0109] In Example 7, the subject matter of Example 6 can further comprise wherein the expiration time is provided to the first NF by the CA or by second NF, the second NF being configured to implement threat detection functionality in the CN.

[0110] In Example 8, the subject matter of Example 6 can further comprise wherein the condition for requesting renewal corresponds to a percentage of validity time allotted to the security certificate.

[0111] In Example 9, the subject matter of any one of the preceding Examples can further comprise wherein the condition for requesting renewal corresponds to a detection, by the second NF, that the security certificate has been compromised.

[0112] In Example 10 the subject matter of any one of the preceding Examples can further comprise wherein the condition corresponds to a detection, by a second NF, that the security certificate has a risk level above a threshold.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0113] In Example 11, the subject matter of any one of the preceding Examples can further comprise, after receiving the security certificate: receiving, from the second NF, a notification that the second NF will request renewal of the security certificate.

[0114] In Example 12, the subject matter of Example 11 can further comprise wherein the notification includes an indication that a software update has been performed by the second NF.

[0115] In Example 13, the subject matter of any of Examples 11-12 can further comprise wherein the notification includes an indication that organizational information associated with the security certificate has changed.

[0116] In Example 14, the subject matter of any of Examples 11-13 can further comprise refraining from transmitting the request based on receiving the notification.

[0117] In Example 15, the subject matter of any one of the preceding Examples can further comprise receiving an indication of whether an authorization challenge is required to implement the request.

[0118] In Example 16, the subject matter of any one of the preceding Examples can further comprise refraining from performing an authorization challenge if the renewed security certificate is not required for NF operations.

[0119] In Example 17, the subject matter of Example 15 can further comprise performing the authorization challenge if the indication indicates that the authorization challenge is required.

[0120] In Example 18, the subject matter of Example 15 or Example 17 can further comprise performing the authorization challenge which comprises repeating the authorization challenge up to a threshold number of times until successful completion of the authorization challenge.

[0121] In Example 19 the subject matter of Example 18 can further comprise wherein the authorization challenge is repeated until a timeout occurs or until successful completion of the authorization challenge.

[0122] In Example 20 the subject matter of Example 19 can further comprise varying a timeout value for each instance of the authorization challenge.

[0123] In Example 21 the subject matter of Example 18 can further comprise re-transmitting the request after successful completion of the authorization challenge.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0124] In Example 22, the subject matter of any one of the preceding Examples can further comprise wherein the request related to the renewal of the security certificate includes an indication of a reason for the transmitting of the request.

[0125] In Example 23 the subject matter of any one of the preceding Examples can further comprise implementing an automated certificate management environment (ACME) protocol.

[0126] In Example 24, the subject matter of Example 23 can further comprise wherein receiving the renewed certificate comprises receiving an ACME message indicating that a resource is created.

[0127] In Example 25, the subject matter of Example 24 can further comprise receiving resource information for the renewed certificate.

[0128] In Example 26, the subject matter of Example 25 can further comprise wherein the resource information includes a uniform resource locator (URL) link.

[0129] In Example 27 the subject matter of Example 24 can further comprise wherein the ACME message comprises a 201 Created message.

[0130] In Example 28, the subject matter of any one of the preceding Examples can further comprise after transmitting the request: transmitting a Certificate Signing Request (CSR) to the CA to request that the CA sign the renewed security certificate; and receiving a signed renewed security certificate in response to the transmitting of the CSR.

[0131] In Example 29, the subject matter of any one of the preceding Examples can further comprise, prior to receiving the renewed security certificate: transmitting a request to download the renewed certificate.

[0132] Example 30 is a method implemented in a certificate authority (CA), the method comprising: transmitting, to a first network function (NF) of a core network (CN), a security certificate; receiving, from the first NF, in response to a trigger event and in accordance with a configuration for the trigger event, a request related to renewal of the security certificate; and transmitting a renewed security certificate in response to the request.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0133] In Example 31, the subject matter of Example 30, further comprising: providing the configuration for the trigger event to the first NF; and receiving the request from the first NF based on the configuration.

[0134] In Example 32, the subject matter of Example 31, further comprising, after the providing the configuration: receiving a notification that the request will be transmitted by a second NF of the CN, the second NF being configured to implement threat detection functionality in the CN.

[0135] In Example 33, the subject matter of Example 30, wherein: the configuration for the trigger event indicates a condition for trigger renewal, the method further comprising: detecting the condition at the CA.

[0136] In Example 34, the subject matter of Example 33, further comprising: transmitting to the first NF, upon detecting the condition, an indication that a renewed certificate is being issued.

[0137] In Example 35, the subject matter of any one of Examples 33-34, further comprising: refraining from transmitting the indication that the renewed certificate is being issued if the security certificate is outside a period of renewal.

[0138] In Example 36, the subject matter of any one of Examples 33-35, further comprising: refraining from transmitting the indication that the renewed certificate is being issued if the first NF is associated with a geographical region outside an authorized geographical region.

[0139] In Example 37, the subject matter of any one of Examples 33-36, further comprising: refraining from transmitting the indication that the renewed certificate is being issued if the first NF is associated with a computer domain outside an authorized computer domain.

[0140] In Example 38, the subject matter of any one of Examples 33-37, wherein: the condition for requesting the renewal is based on an expiration time of the security certificate.

[0141] In Example 39, the subject matter of Example 38, wherein: the expiration time is provided by the CA or by the threat detection NF.

[0142] In Example 40, the subject matter of Example 38, wherein: the condition for requesting renewal corresponds to a percentage of validity time allotted to the security certificate.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0143] In Example 41, the subject matter of any one of Examples 33-40, wherein: the condition for requesting renewal corresponds to a detection, by the threat detection NF, that the security certificate has been compromised.

[0144] In Example 42, the subject matter of any one of Examples 33-41, wherein: the condition corresponds to a detection, by the threat detection NF, that the security certificate has a risk level above a threshold.

[0145] In Example 43, the subject matter of any one of Examples 30-42, further comprising, prior to the receiving the request: transmitting, to the first NF, an indication of whether an authorization challenge is required before renewal of the security certificate.

[0146] In Example 44, the subject matter of Example 43, further comprising: accessing a list of automatic certificate management environment (ACME) clients that are pre-authorized for certificate renewal; and transmitting the authorization challenge if the first NF is not found on the list.; and transmitting a notification that the authorization challenge is not required otherwise.

[0147] In Example 45, the subject matter of Example 43 wherein, when the authorization challenge is required, the method further comprises: implementing the authorization challenge.

[0148] In Example 46, the subject matter of Example 45, wherein the authorization challenge comprises: repeating the authorization challenge up to a threshold number of times until successful completion of the authorization challenge.

[0149] In Example 47, the subject matter of Example 46, wherein: the authorization challenge is repeated until a timeout occurs or until successful completion of the authorization challenge.

[0150] In Example 48, the subject matter of Example 47, wherein: varying a timeout value varies for each instance of the authorization challenge.

[0151] In Example 49, the subject matter of Example 44, further comprising: receiving the request or a re-request after successful completion of the authorization challenge.

[0152] In Example 50, the subject matter of any one of Examples 30-49, wherein: the request includes an indication of a reason for the request.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0153] In Example 51, the subject matter of Example 50, further comprising: providing the reason for the request as training data to a machine learning model implemented in a data analysis NF.

[0154] In Example 52, the subject matter of Example 51, further comprising: obtaining training data including reasons for certificate action requests, and vulnerability levels of historical security certificates; providing the training data to the data analysis NF to train the machine learning model to predict a vulnerability level of a new security certificate based on reasons for certificate action requests associated with the new security certificate; and receiving a request to trigger certificate renewal based on the predicted vulnerability level.

[0155] In Example 53, the subject matter of Example 52, further comprising: accessing a system to track state information for a plurality of security certificates; and updating an expiration date for at least one security certificate based on the predicted vulnerability level.

[0156] In Example 54, the subject matter of any one of Examples 30-53, wherein: transmitting the security certificate to the NF comprises implementing an automated certificate management environment (ACME) protocol.

[0157] In Example 55, the subject matter of Example 54, wherein: transmitting the renewed certificate comprises transmitting an ACME message indicating that a resource is created.

[0158] In Example 56, the subject matter of 55, further comprising: transmitting resource information for the renewed certificate.

[0159] In Example 57, the subject matter of Example 56, wherein: the resource information includes a uniform resource locator (URL) link.

[0160] In Example 58, the subject matter of Example 55, wherein: the ACME message comprises a 201 Created message.

[0161] In Example 59, the subject matter of any one of Examples 30-58, further comprising, after receiving the request: receiving a Certificate Signing Request (CSR) to sign the renewed security certificate; and transmitting a signed renewed security certificate in response to the receiving of the CSR.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00

[0162] In Example 60, the subject matter of any one of Examples 30-59, further comprising, prior to transmitting the renewed security certificate: receiving a request to download the renewed certificate.

[0163] In Example 61, the subject matter of any one of Examples 30-60, wherein: the CA implements ACME server functions of the ACME enrollment process.

[0164] In Example 62, a network device comprises a transceiver; and processing hardware configured to implement a method of any of the preceding Examples.

[0165] The following description may be applied to the description above.

[0166] Certain embodiments are described in this disclosure as including logic or a number of components or modules. Modules can be software modules (e.g., code stored on non-transitory machine-readable medium) or hardware modules. A hardware module is a tangible unit capable of performing certain operations and may be configured or arranged in a certain manner. A hardware module can comprise dedicated circuitry or logic that is permanently configured (e.g., as a special-purpose processor, such as a field programmable gate array (FPGA) or an application-specific integrated circuit (ASIC)) to perform certain operations. A hardware module may also comprise programmable logic or circuitry (e.g., as encompassed within a general- purpose processor or other programmable processor) that is temporarily configured by software to perform certain operations. The decision to implement a hardware module in dedicated and permanently configured circuitry, or in temporarily configured circuitry (e.g., configured by software) may be driven by cost and time considerations.

[0167] When implemented in software, the techniques can be provided as part of the operating system, a library used by multiple applications, a particular software application, etc. The software can be executed by one or more general-purpose processors or one or more special- purpose processors.

[0168] As used herein, the terms “comprises,” “comprising,” “includes,” “including,” “has,” “having” or any other variation thereof, are intended to cover a non-exclusive inclusion. For example, a process, method, article, or apparatus that comprises a list of elements is not necessarily limited to only those elements but may include other elements not expressly listed or inherent to such process, method, article, or apparatus. Further, unless expressly stated to thePATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 contrary, “or” refers to an inclusive or and not to an exclusive or. For example, a condition A or B is satisfied by any one of the following: A is true (or present), and B is false (or not present), A is false (or not present), and B is true (or present), and both A and B are true (or present)

Claims

PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 What is claimed is:

1. A method implemented in a first network function (NF) of a core network (CN), the method comprising: receiving, from a certificate authority (CA), a security certificate and a configuration that defines conditions for a trigger event, the conditions being based on policies for certificate renewal; transmitting to the CA, in response to the trigger event, a request related to renewal of the security certificate; and receiving a renewed security certificate in response to the request.

2. The method of claim 1, wherein: the conditions include an expiration time of the security certificate.

3. The method of claim 1, wherein: the conditions are based on a detection that the security certificate has been compromised.

4. The method of any of claims 1-3, wherein: the conditions include a prediction that the security certificate has a risk level above a threshold.

5. The method of any of claims 1-4, further comprising: receiving an indication of whether an authorization challenge is required to implement the request.

6. The method of any of claims 1-5, further comprising: refraining from performing an authorization challenge if the renewed security certificate is not required for NF operations.

7. The method of any of claims 1-6, further comprising: implementing an automated certificate management environment (ACME) protocol.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 8. A method implemented in a certificate authority (CA), the method comprising: transmitting, to a first network function (NF) of a core network (CN), a security certificate and a configuration that defines conditions for a trigger event, the conditions being based on policy configurations for certificate renewal; receiving, from the first NF, in accordance with the configuration for the trigger event, a request related to renewal of the security certificate; and transmitting a renewed security certificate in response to the request.

9. The method of claim 8, wherein: the configuration includes a certificate expiration time defined by the CA.

10. The method of claim 8, further comprising, after providing the configuration: receiving a notification that the request will be transmitted by a second NF of the CN, the second NF being configured to implement threat detection functionality in the CN.

11. The method of claim 9, further comprising: refraining from transmitting the renewed security certificate if the first NF is associated with a geographical region outside an authorized geographical region or if the first NF is associated with a computer domain outside an authorized computer domain.

12. The method of claim 9, further comprising: accessing a list of automatic certificate management environment (ACME) clients that are pre-authorized for certificate renewal; and transmitting an authorization challenge if the first NF is not found on the list of ACME clients that are pre-authorized for certificate renewal, and transmitting a notification that the authorization challenge is not required otherwise.

13. The method of claim 12, wherein the authorization challenge comprises: repeating the authorization challenge up to a threshold number of times until successful completion of the authorization challenge.PATENT APPLICATION Attorney Docket No.: 31730 / 308374-00 14. The method of claim 9, further comprising: obtaining training data including reasons for certificate action requests, and vulnerability levels of historical security certificates; providing the training data to a data analysis NF to train a machine learning model to predict a vulnerability level of a new security certificate based on reasons for certificate action requests associated with the new security certificate; and receiving a request to trigger certificate renewal based on the predicted vulnerability level.

15. A network device comprising: processing hardware; and a transceiver, the network device configured to implement a method of any of the preceding claims.

Citation Information

Patent Citations

  • Internet of Things equipment certificate automatic updating method and device and storage medium

    CN112613021A