Credential Vault Onboarding for Network Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network infrastructure lacks an efficient and automated method for onboarding a large number of network functions to a credential vault, which is essential for secure authentication and communication.

Innovation Solution

A method and system for automatically onboarding network functions to a credential vault by establishing a cluster account, configuring the vault processor for authentication, generating identifiers for network functions, setting initialization parameters, assigning access permissions, and associating network functions with the cluster account.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual onboarding methods are used for network functions, then security and authentication can be maintained, but the process becomes time-consuming and inefficient when onboarding a large number of network functions

Engineering Contradiction:
Improveonboarding efficiencyVSAvoidonboarding time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables automated self-service onboarding where the credential vault processor automatically generates credentials, assigns permissions, and configures network functions without manual intervention. The NF itself can request and receive its credentials through the automated process, eliminating the need for manual configuration while maintaining security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring credential storage structures, authentication codes, and permission frameworks in the credential vault before network functions need to be onboarded. This preparation enables rapid automated onboarding of multiple NFs simultaneously without requiring manual setup for each function.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated onboarding is implemented for network functions, then onboarding efficiency improves, but system complexity increases due to automated credential management and permission assignment

Engineering Contradiction:
Improveonboarding efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The credential vault processor is designed as a universal system that handles multiple functions: generating authentication codes, creating credentials, assigning permissions, and managing credential storage for different types of network functions. This multi-functional approach consolidates complexity into a single standardized platform rather than requiring separate systems for each onboarding task.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity through parameterized credential generation, where credentials are created with configurable parameters such as permission levels, validity periods, and access scopes. By changing parameters rather than creating entirely different credential structures, the system handles diverse onboarding requirements through a unified process, reducing overall system complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If credentials are stored in the credential vault for network functions, then secure authentication is enabled, but access control and permission management become more challenging

Engineering Contradiction:
Improveauthentication securityVSAvoidpermission management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments permission management into distinct hierarchical levels: cluster-level permissions for groups of network functions and individual NF-level permissions for specific functions. This segmentation allows administrators to manage permissions at appropriate granularities, reducing complexity while maintaining secure authentication for each network function through the credential vault.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12326927B2System and method for automatic onboarding of network functions to a credential vault
Publication Date: 2025.06.10 RAKUTEN SYMPHONY INC
  • US12326927B2 patent drawing
  • US12326927B2 patent drawing
  • US12326927B2 patent drawing

AI summary

To automatically onboard network functions to a credential vault, a orchestration processor actuates establishment of an cluster account for a network cluster, and actuates a cluster configuration of a processor of the vault to enable authentication of a network cluster. For each of a plurality of network functions associated with the network cluster, the orchestration processor generates an identifier, sets values for parameters of an initialization parameter set, actuates assignment of access permissions for a code address on a memory of the vault, actuates assignment of elevated access permissions for a credential address on the vault memory, and actuates association of the network function with a cluster account of the network cluster. The vault memory thereby defines credential addresses each corresponding to a respective network function.