PKI Credential Allocation for Wireless Base Station Radio Units

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of 5G wireless base stations, there is a challenge in securely installing unique digital certificates and private keys in radio units, especially for newly fabricated or deployed units that lack internet access, and in ensuring secure authentication and communication between radio units and distributed units using public key infrastructure (PKI) credentials.

Innovation Solution

A system and method for securely obtaining and storing PKI credentials in wireless base station radio units involve generating an AuthToken, which includes a timestamp and MAC address, signed by a controller or PKI support station, to request and receive a digital certificate and private key from an online provision service certificate authority, ensuring authentication and secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If radio units are deployed without pre-installed PKI credentials, then device complexity and deployment cost are reduced, but security authentication capability is compromised

Engineering Contradiction:
Improvedeployment complexityVSAvoidsecurity authentication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-configuring the radio unit with a global key and authentication mechanism during manufacturing, enabling it to autonomously request and obtain PKI credentials from the OPS CA after deployment without requiring manual intervention or pre-installed certificates

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The radio unit autonomously services its own PKI credential acquisition by using its global key to sign a request message, receiving the signed certificate and private key from the OPS CA, and storing them locally without requiring external assistance or complex deployment procedures

Inventive Principle:
Principle #25Self-service

2Reliability

If manual PKI credential installation is performed, then security authentication is ensured, but deployment time and operational complexity increase

Engineering Contradiction:
Improvesecurity authenticationVSAvoiddeployment operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The radio unit autonomously completes the entire PKI credential acquisition process by initiating a request to the OPS CA, receiving the signed certificate and private key, and storing them locally without requiring manual intervention, thereby ensuring security while simplifying deployment operations

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration of the global key and authentication mechanisms during manufacturing, enabling the radio unit to self-service its PKI credential acquisition after deployment without requiring complex manual operations

Inventive Principle:
Principle #10Preliminary action

3Reliability

If PKI credentials are pre-installed in radio units, then security authentication is guaranteed, but manufacturing complexity and cost increase

Engineering Contradiction:
Improvesecurity authenticationVSAvoidmanufacturing process
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system performs only minimal preliminary actions during manufacturing by pre-installing a global key and authentication mechanism in the radio unit, rather than installing complete PKI credentials, thereby reducing manufacturing complexity while enabling autonomous credential acquisition after deployment

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12063502B2Systems and methods for PKI certificate and key allocations to wireless base station radio units
Publication Date: 2024.08.13 OUTDOOR WIRELESS NETWORKS LLC
  • US12063502B2 patent drawing
  • US12063502B2 patent drawing
  • US12063502B2 patent drawing

AI summary

Systems and methods for PKI certificate and key allocations to wireless base station radio units are provided. In one embodiment, a system for obtaining PKI credentials for a remote unit for a wireless base station, the system comprises: a remote unit, the remote unit configured to implement a radio frequency (RF) interface; a gateway coupled to the remote unit, the gateway communicatively coupled to an online provision service (OPS) certificate authority (CA); wherein the gateway is configured to generate an AuthToken unique to the remote unit, wherein the remote unit is configured to request a RU digital certificate and private key from an OPS CA based on the AuthToken.