Automatic certificate management in 5gc network
US-2023412396-A1 · Dec 21, 2023 · US
US12580905B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12580905-B2 |
| Application number | US-202318207117-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 7, 2023 |
| Priority date | Jun 7, 2023 |
| Publication date | Mar 17, 2026 |
| Grant date | Mar 17, 2026 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method for automatically binding an SBI communications digital certificate lifecycle to an NF lifecycle includes receiving, at an NRF, an NF deregister request message for deregistering an NF. The method further includes generating, by the NRF and in response to the NF deregister request message or successful completion of deregistration of the NF, a certificate revocation request message for revoking at least one digital certificate used by NF for SBI communications. The method further includes transmitting, by the NRF, the certificate revocation request message to a certificate authority. The method further includes receiving, by the NRF, an NF register request message identifying the NF. The method further includes determining, by the NRF, that the at least one digital certificate of the NF has been revoked. The method further includes, in response to determining that the at least one digital certificate of the NF has been revoked, performing, by the NRF, a network security action in response to the NF register request message.
Opening claim text (preview).
What is claimed is: 1 . A method for automatically binding a service-based interface (SBI) communications digital certificate lifecycle to a network function (NF) lifecycle, the method comprising: receiving, at an NF repository function (NRF), an NF deregister request message generated by an NF for deregistering the NF, wherein the NF is a 5G NF and the NF deregister request message is transmitted by the 5G NF for the 5G NF to indicate to the NRF that the 5G NF is decommissioning itself and that communications from the 5G NF should not appear in a 5G network; generating, by the NRF and automatically in response to the NF deregister request message generated by the 5G NF or successful completion of deregistration of the 5G NF in response to the NF deregister request message generated by the 5G NF, a certificate revocation request message for revoking at least one digital certificate used by the 5G NF for SBI communications; transmitting, by the NRF, the certificate revocation request message to a certificate authority; receiving, by the NRF, an NF register request message identifying the 5G NF; determining, by the NRF, that the at least one digital certificate of the 5G NF has been revoked; and in response to determining that the at least one digital certificate of the NF has been revoked, performing, by the NRF, a network security action in response to the NF register request message, wherein performing the network security action includes rejecting the NF register request message. 2 . The method of claim 1 wherein generating the certificate revocation request message includes generating a request message for revoking a digital certificate corresponding to an NF instance ID of the NF. 3 . The method of claim 2 wherein generating the certificate revocation request includes embedding the NF instance ID in the digital certificate and including the digital certificate in the certificate revocation request message. 4 . The method of claim 1 wherein generating the certificate revocation request message includes generating a certificate management protocol (CMP) certificate revocation request message. 5 . The method of claim 1 wherein generating the certificate revocation request message includes generating the certificate revocation request message for revoking at least a transport layer security (TLS) certificate used by the NF for SBI communications. 6 . The method of claim 1 wherein generating the certificate revocation request message includes generating the certificate revocation request message for revoking at least an OAuth 2.0 certificate used by the NF for SBI communications. 7 . The method of claim 1 wherein generating the certificate revocation request message includes generating the certificate revocation request message for revoking at least a client credentials assertion (CCA) certificate used by the NF for SBI communications. 8 . The method of claim 1 wherein determining that the at least one digital certificate has been revoked includes querying, by the NRF, the certificate authority to determine the status of the at least one digital certificate. 9 . The method of claim 1 comprising receiving, by the certificate authority, the certificate revocation request message and revoking the at least one digital certificate of the NF. 10 . A system for automatically binding a service-based interface (SBI) communications digital certificate lifecycle to a network function (NF) lifecycle, the system comprising: an NF repository function (NRF) including at least one processor and a memory; an NF register/deregister handler implemented by the at least one processor for receiving an NF deregister request message generated by an NF for deregistering the NF, wherein the NF is a 5G NF and the NF deregister request message is transmitted by the 5G NF for the 5G NF to indicate to the NRF that the 5G NF is decommissioning itself and that communications from the 5G NF should not appear in a 5G network; a certificate manager implemented by the at least one processor for generating, automatically in response to the NF deregister request message generated by the NF or successful completion of deregistration of the 5G NF in response to the NF deregister request message generated by the 5G NF, a certificate revocation request message for revoking at least one digital certificate used by the 5G NF for service-based interface (SBI) communications and transmitting, by the NRF, the certificate revocation request message to a certificate authority; wherein the NF register/deregister handler is configured to receive an NF register request message identifying the 5G NF; wherein the certificate manager is configured to determine that the at least digital one certificate of the 5G NF has been revoked; and wherein the NF register/deregister handler is configured to, in response to the determination that that the at least one digital certificate of the 5G NF has been revoked, perform a network security action in response to the NF register request message, wherein performing the network security action includes rejecting the NF register request message. 11 . The system of claim 10 wherein the certificate revocation request message includes an NF instance ID of the NF for revoking a digital certificate corresponding to the NF instance ID of the NF. 12 . The system of claim 11 wherein the NF instance ID is embedded in the digital certificate, which is included in the certificate revocation request message. 13 . The system of claim 10 wherein the certificate revocation request message includes a certificate management protocol (CMP) certificate revocation request message. 14 . The system of claim 10 wherein the certificate revocation request message includes a request message for revoking at least a transport layer security (TLS) certificate used by the NF for SBI communications. 15 . The system of claim 10 wherein the certificate revocation request message includes a request message for revoking at least an OAuth 2.0 certificate used by the NF for SBI communications. 16 . The system of claim 10 wherein the certificate revocation request message includes a request message for revoking at least a client credentials assertion (CCA) certificate used by the NF for SBI communications. 17 . The system of claim 10 wherein in determining that the at least one digital certificate has been revoked, the certificate manager is configured to query the certificate authority to determine the status of the at least one digital certificate. 18 . A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising: receiving, at a network function (NF) repository function (NRF), an NF deregister request message generated by an NF for deregistering the NF, wherein the NF is a 5G NF and the NF deregister request message is transmitted by the 5G NF for the 5G NF to indicate to the NRF that the 5G NF is decommissioning itself and that communications from the 5G NF should not appear in a 5G network; generating, by the NRF and automatically in response to the NF deregister request message generated by the 5G NF or successful completion of deregistration of the 5G NF in response to the NF deregister request message generated by the 5G NF, a certificate revocation request message for revoking at least one digital certificate used by the 5G NF for service-based interface (SBI) communications; transmitting, by the NRF, the certificate revocation req
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.