Private PKI Certificate Provisioning for Virtual Network Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual network functions in networks face challenges in obtaining certificates from public CAs, leading to increased computing resource usage, security vulnerabilities, and delays in network modifications due to inefficient identity verification processes.

Innovation Solution

Implementing a private PKI with a network function orchestrator, life cycle manager, and private CA to manage certificates for virtual network functions, ensuring quick identity verification and secure storage within the network, reducing resource usage and mitigating security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual network functions obtain certificates from public CAs, then identity verification is performed, but computing resource usage increases and security vulnerabilities arise

Engineering Contradiction:
Improveidentity verificationVSAvoidcomputing resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a private CA as an intermediary within the network that issues certificates to virtual network functions. This private CA acts as a trusted mediator that enables identity verification without requiring external public CA interactions, thereby reducing computing resource usage while maintaining verification reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the certificate management function from the public CA infrastructure and creates a dedicated private CA component within the network. This segmentation allows the network to handle certificate issuance and verification internally, reducing dependency on external resources and minimizing computing overhead

Inventive Principle:
Principle #1Segmentation

2Reliability

If virtual network functions obtain certificates from public CAs, then identity verification is performed, but security vulnerabilities increase

Engineering Contradiction:
Improveidentity verificationVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The private CA serves as a controlled intermediary that operates within the network's security perimeter. By mediating certificate issuance internally rather than relying on external public CAs, the system eliminates exposure to external security threats while maintaining robust identity verification capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a secure, isolated environment for certificate management by implementing a private CA within the network. This inert environment protects the certificate issuance and verification processes from external security threats and vulnerabilities associated with public CA interactions

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Adaptability or versatility

If public PKI is used for certificate management, then certificates can be obtained, but network modification delays occur

Engineering Contradiction:
Improvenetwork modification capabilityVSAvoidnetwork modification delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The private CA is pre-configured within the network infrastructure, eliminating the need for real-time external CA interactions when network modifications are required. Certificates can be issued immediately to new virtual network functions without waiting for external CA processing, enabling rapid network adaptation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network implements self-service certificate management through the private CA, which autonomously handles certificate issuance and verification internally. This eliminates dependency on external public CA services and enables immediate certificate provisioning when network functions are added or modified

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12500778B2Systems and methods for managing public key infrastructure certificates for components of a network
Publication Date: 2025.12.16 VERIZON PATENT & LICENSING INC
  • US12500778B2 patent drawing
  • US12500778B2 patent drawing
  • US12500778B2 patent drawing

AI summary

A device may determine that a network function of a network has been instantiated to facilitate communication via the network. The device may request a certificate authority to provide a certificate for the network function. The device may receive, from the certificate authority, the certificate. The device may generate a certificate profile to enable other network functions of the network to authenticate communications with the network function, wherein the certificate profile identifies: the certificate and a certification protocol. The device may provide, to the network function, the certificate profile to cause the network function to use the certificate to communicate with the other network functions.