Methods, systems, and computer readable media for using service communication proxy (SCP) to offload verification of consumer network function (NF) security certificates

US12506728B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12506728-B2
Application numberUS-202418741748-A
CountryUS
Kind codeB2
Filing dateJun 12, 2024
Priority dateJun 12, 2024
Publication dateDec 23, 2025
Grant dateDec 23, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for offloading verification of consumer NF security certificates includes receiving, by an SCP, an SBI request message including a consumer NF security token signed by a consumer NF for authenticating the consumer NF to a producer NF. The method further includes obtaining, by the SCP and from the consumer NF security token, an identifier for a consumer NF security certificate or a copy of the consumer NF security certificate. The method further includes verifying, by the SCP and on behalf of the producer NF, the consumer NF security certificate. The method further includes performing, by the SCP and based on a verification result of the consumer NF security certificate, a network security action.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for offloading verification of consumer network function (NF) security certificates, the method comprising: receiving, by a service communication proxy (SCP), a service-based interface (SBI) request message including a consumer NF security token signed by a consumer NF for authenticating the consumer NF to a producer NF; obtaining, by the SCP and from the consumer NF security token, an identifier for a consumer NF security certificate or a copy of the consumer NF security certificate; verifying, by the SCP and on behalf of the producer NF, the consumer NF security certificate; and performing, by the SCP and based on a verification result of the consumer NF security certificate, a network security action. 2 . The method of claim 1 wherein receiving an SBI request message including a consumer NF security token includes receiving an SBI request message including a client credentials assertion (CCA) token. 3 . The method of claim 1 wherein obtaining the identifier of the consumer NF security certificate or the copy of the consumer NF security certificate includes obtaining an identifier or a copy of an X.509 certificate from the consumer NF security token. 4 . The method of claim 1 wherein verifying the consumer NF security certificate includes determining, by the SCP, whether the SCP has a valid cached verification result for the consumer NF security certificate. 5 . The method of claim 4 wherein, when the SCP has a valid cached verification result for the consumer NF security certificate, performing the network security action includes performing the network security action based on the cached verification result. 6 . The method of claim 4 wherein, when the SCP does not have a valid cached verification result for the consumer NF security certificate, verifying the consumer NF security certificate includes: transmitting, by the SCP and on behalf of the producer NF, an online certificate status protocol (OCSP) request message to a certificate authority (CA); and receiving, by the SCP and from the CA, an OCSP response message including the verification result and wherein the method further comprises caching, by the SCP, the verification result. 7 . The method of claim 6 wherein performing the network security action includes appending the verification result to the SBI request message and transmitting the SBI request message to the producer NF. 8 . The method of claim 4 wherein, when the SCP does not have a valid cached verification result for the consumer NF security certificate, verifying the consumer NF security certificate includes: checking, by the SCP and on behalf of the producer NF, a certificate revocation list (CRL); and determining the verification result from the CRL. 9 . The method of claim 1 wherein the verification result indicates that the consumer NF security certificate has expired or has been revoked and performing the network security action includes rejecting the SBI request message. 10 . The method of claim 9 wherein rejecting the SBI request message includes dropping the SBI request message and/or generating a fake response to the SBI request message. 11 . A system for offloading verification of consumer network function (NF) security certificates, the system comprising: a service communication proxy (SCP) including at least one processor and a memory; and a consumer NF security certificate verification offload manager for receiving a service-based interface (SBI) request message including a consumer NF security token signed by a consumer NF for authenticating the consumer NF to a producer NF, obtaining, from the consumer NF security token, an identifier for a consumer NF security certificate or a copy of the consumer NF security certificate, verifying, on behalf of the producer NF, the consumer NF security certificate, and performing, based on a verification result of the consumer NF security certificate, a network security action. 12 . The system of claim 11 wherein the consumer NF security token comprises a client credentials assertion (CCA) token. 13 . The system of claim 11 wherein the identifier of the consumer NF security certificate or the copy of the consumer NF security certificate comprises an identifier or a copy of an X.509 certificate. 14 . The system of claim 11 wherein, in verifying the consumer NF security certificate, the consumer NF security certificate verification offload manager is configured to determine whether the SCP has a valid cached verification result for the consumer NF security certificate. 15 . The system of claim 14 wherein, when the SCP has a valid cached verification result for the consumer NF security certificate, the consumer NF security certificate verification offload manager is configured to perform the network security action based on the cached verification result. 16 . The system of claim 14 wherein, when the SCP does not have a valid cached verification result for the consumer NF security certificate, the consumer NF security certificate verification offload manager is configured to verify the consumer NF security certificate by: transmitting, by the SCP and on behalf of the producer NF, an online certificate status protocol (OCSP) request message to a certificate authority (CA); and receiving, by the SCP and from the CA, an OCSP response message including the verification result and wherein the consumer NF security certificate verification offload manager is further configured to cache the verification result. 17 . The system of claim 16 wherein the consumer NF security certificate verification offload manager is configured to perform the network security action by appending the verification result to the SBI request message and transmitting the SBI request message to the producer NF. 18 . The system of claim 14 wherein, when the SCP does not have a valid cached verification result for the consumer NF security certificate, the consumer NF security certificate verification offload manager is configured to verify the consumer NF security certificate by: checking, on behalf of the producer NF, a certificate revocation list (CRL); and determining the verification result from the CRL. 19 . The system of claim 11 wherein the verification result indicates that the consumer NF security certificate has been revoked and to perform the network security action by rejecting the SBI request message including dropping the SBI request message and/or generating a fake response to the SBI request message. 20 . A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising: receiving, by a service communication proxy (SCP), a service-based interface (SBI) request message including a consumer NF security token signed by a consumer NF for authenticating the consumer NF to a producer NF; obtaining, by the SCP and from the consumer NF security token, an identifier for a consumer NF security certificate or a copy of the consumer NF security certificate; verifying, by the SCP and on behalf of the producer NF, the consumer NF security certificate; and performing, by the SCP and based on a verification result of the consumer NF security certificate, a network security action.

Assignees

Inventors

Classifications

  • using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL] · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • H04L9/3213Primary

    using tickets or tokens, e.g. Kerberos (network architectures or network communication protocols for entities authentication using tickets in a packet data network H04L63/0807) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12506728B2 cover?
A method for offloading verification of consumer NF security certificates includes receiving, by an SCP, an SBI request message including a consumer NF security token signed by a consumer NF for authenticating the consumer NF to a producer NF. The method further includes obtaining, by the SCP and from the consumer NF security token, an identifier for a consumer NF security certificate or a copy…
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/0823. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 23 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).