PKI Credential Allocation for Wireless Base Station Radio Units
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of 5G wireless base stations, there is a challenge in securely installing unique digital certificates and private keys in radio units, especially for newly fabricated or deployed units that lack internet access, and in ensuring secure authentication and communication between radio units and distributed units using public key infrastructure (PKI) credentials.
Innovation Solution
A system and method for securely obtaining and storing PKI credentials in wireless base station radio units involve generating an AuthToken, which includes a timestamp and MAC address, signed by a controller or PKI support station, to request and receive a digital certificate and private key from an online provision service certificate authority, ensuring authentication and secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If radio units are deployed without pre-installed PKI credentials, then device complexity and deployment cost are reduced, but security authentication capability is compromised
Solution Approach 1:
The system performs preliminary actions by pre-configuring the radio unit with a global key and authentication mechanism during manufacturing, enabling it to autonomously request and obtain PKI credentials from the OPS CA after deployment without requiring manual intervention or pre-installed certificates
Solution Approach 2:
The radio unit autonomously services its own PKI credential acquisition by using its global key to sign a request message, receiving the signed certificate and private key from the OPS CA, and storing them locally without requiring external assistance or complex deployment procedures
2Reliability
If manual PKI credential installation is performed, then security authentication is ensured, but deployment time and operational complexity increase
Solution Approach 1:
The radio unit autonomously completes the entire PKI credential acquisition process by initiating a request to the OPS CA, receiving the signed certificate and private key, and storing them locally without requiring manual intervention, thereby ensuring security while simplifying deployment operations
Solution Approach 2:
The system performs preliminary configuration of the global key and authentication mechanisms during manufacturing, enabling the radio unit to self-service its PKI credential acquisition after deployment without requiring complex manual operations
3Reliability
If PKI credentials are pre-installed in radio units, then security authentication is guaranteed, but manufacturing complexity and cost increase
Solution Approach 1:
The system performs only minimal preliminary actions during manufacturing by pre-installing a global key and authentication mechanism in the radio unit, rather than installing complete PKI credentials, thereby reducing manufacturing complexity while enabling autonomous credential acquisition after deployment
Data Source
AI summary
Systems and methods for PKI certificate and key allocations to wireless base station radio units are provided. In one embodiment, a system for obtaining PKI credentials for a remote unit for a wireless base station, the system comprises: a remote unit, the remote unit configured to implement a radio frequency (RF) interface; a gateway coupled to the remote unit, the gateway communicatively coupled to an online provision service (OPS) certificate authority (CA); wherein the gateway is configured to generate an AuthToken unique to the remote unit, wherein the remote unit is configured to request a RU digital certificate and private key from an OPS CA based on the AuthToken.


