Certificate Enrollment for Multi-Vendor Network Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The traditional network architecture for radio access networks is inadequate in supporting multiple vendor-specific network elements, and existing authentication and verification methods are insufficient for securing network communication in a multi-vendor environment.
Innovation Solution
A system and method for non-virtual machine based network elements to perform certificate enrollment through a Certificate Authority server, utilizing a DHCP server, Authentication server, Registration Authority server, and Certificate Authority server for fully automated enrollment, and a Certificate Lifecycle Management System for semi-automated enrollment, enabling secure and efficient authentication of NEs from different vendors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional network architecture is used, then vendor-specific network elements can be supported, but multi-vendor environment and diverse NE types cannot be supported
Solution Approach 1:
The system segments the authentication function from the DHCP server by introducing a dedicated Authentication Server. This separation allows the DHCP server to maintain its existing functionality while the Authentication Server handles vendor-specific authentication protocols, enabling multi-vendor support without increasing overall system complexity
Solution Approach 2:
The Authentication Server acts as an intermediary between the DHCP server and network elements from different vendors. It translates various vendor-specific authentication mechanisms into a unified authentication framework, allowing diverse NE types to be supported through a single interface
2Reliability
If traditional authentication methods are used, then single-vendor security can be maintained, but multi-vendor security cannot be ensured
Solution Approach 1:
The Authentication Server implements universal authentication capabilities that work across multiple vendor platforms. It supports multiple authentication protocols and can verify certificates from different Certificate Authorities, ensuring network security while maintaining multi-vendor compatibility
Solution Approach 2:
The system changes the authentication parameter from vendor-specific credentials to standardized certificates issued by trusted Certificate Authorities. This parameter change enables secure authentication across different vendors while maintaining reliability through cryptographic verification
3Extent of automation
If manual certificate enrollment is used, then certificate issuance can be controlled, but human error and information leakage increase
Solution Approach 1:
The certificate enrollment process is designed as a self-service automated system where the Network Element autonomously generates certificate signing requests, receives approval from the Certificate Authority, and obtains its certificate without human intervention. This eliminates human error and information leakage while maintaining control through predefined policies
Solution Approach 2:
The automated enrollment system implements feedback mechanisms where the Authentication Server monitors the enrollment process, verifies certificate validity, and enforces security policies. This automated feedback loop ensures enrollment security while maintaining high automation levels
4Device complexity
If authentication is handled by DHCP server, then centralized control is achieved, but DHCP server load increases
Solution Approach 1:
The system segments the authentication workload from the DHCP server by creating a dedicated Authentication Server. The DHCP server retains only lightweight authentication verification functions, while the Authentication Server handles the computationally intensive authentication processes, thereby reducing DHCP server load while maintaining centralized control
Data Source
AI summary
A system for performing full-automated enrollment of certificates in a mobile communications network, includes: a network element configured to request a certificate; at least one server configured to authenticate the network element and provide certificate authority (CA) information to the network element; and a certificate manager configured to obtain a preconfigured policy for the requested certificate, obtain the certificate based on the preconfigured policy, and issue the certificate to the network element, wherein the network element is configured to: send, to the at least one server, a request for obtaining information on the certificate manager; obtain, from the at least one server, the information on the certificate manager; send, to the certificate manager based on the obtained information on the certificate manager, a certificate signing request (CSR) for requesting the certificate; and receive, from the certificate manager, the requested certificate generated by a CA server of the certificate manager.


