Methods, systems, and computer readable media for automatically binding a service-based interface (SBI) communications digital certificate lifecycle to a network function (NF) lifecycle

US12580905B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12580905-B2
Application numberUS-202318207117-A
CountryUS
Kind codeB2
Filing dateJun 7, 2023
Priority dateJun 7, 2023
Publication dateMar 17, 2026
Grant dateMar 17, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for automatically binding an SBI communications digital certificate lifecycle to an NF lifecycle includes receiving, at an NRF, an NF deregister request message for deregistering an NF. The method further includes generating, by the NRF and in response to the NF deregister request message or successful completion of deregistration of the NF, a certificate revocation request message for revoking at least one digital certificate used by NF for SBI communications. The method further includes transmitting, by the NRF, the certificate revocation request message to a certificate authority. The method further includes receiving, by the NRF, an NF register request message identifying the NF. The method further includes determining, by the NRF, that the at least one digital certificate of the NF has been revoked. The method further includes, in response to determining that the at least one digital certificate of the NF has been revoked, performing, by the NRF, a network security action in response to the NF register request message.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for automatically binding a service-based interface (SBI) communications digital certificate lifecycle to a network function (NF) lifecycle, the method comprising: receiving, at an NF repository function (NRF), an NF deregister request message generated by an NF for deregistering the NF, wherein the NF is a 5G NF and the NF deregister request message is transmitted by the 5G NF for the 5G NF to indicate to the NRF that the 5G NF is decommissioning itself and that communications from the 5G NF should not appear in a 5G network; generating, by the NRF and automatically in response to the NF deregister request message generated by the 5G NF or successful completion of deregistration of the 5G NF in response to the NF deregister request message generated by the 5G NF, a certificate revocation request message for revoking at least one digital certificate used by the 5G NF for SBI communications; transmitting, by the NRF, the certificate revocation request message to a certificate authority; receiving, by the NRF, an NF register request message identifying the 5G NF; determining, by the NRF, that the at least one digital certificate of the 5G NF has been revoked; and in response to determining that the at least one digital certificate of the NF has been revoked, performing, by the NRF, a network security action in response to the NF register request message, wherein performing the network security action includes rejecting the NF register request message. 2 . The method of claim 1 wherein generating the certificate revocation request message includes generating a request message for revoking a digital certificate corresponding to an NF instance ID of the NF. 3 . The method of claim 2 wherein generating the certificate revocation request includes embedding the NF instance ID in the digital certificate and including the digital certificate in the certificate revocation request message. 4 . The method of claim 1 wherein generating the certificate revocation request message includes generating a certificate management protocol (CMP) certificate revocation request message. 5 . The method of claim 1 wherein generating the certificate revocation request message includes generating the certificate revocation request message for revoking at least a transport layer security (TLS) certificate used by the NF for SBI communications. 6 . The method of claim 1 wherein generating the certificate revocation request message includes generating the certificate revocation request message for revoking at least an OAuth 2.0 certificate used by the NF for SBI communications. 7 . The method of claim 1 wherein generating the certificate revocation request message includes generating the certificate revocation request message for revoking at least a client credentials assertion (CCA) certificate used by the NF for SBI communications. 8 . The method of claim 1 wherein determining that the at least one digital certificate has been revoked includes querying, by the NRF, the certificate authority to determine the status of the at least one digital certificate. 9 . The method of claim 1 comprising receiving, by the certificate authority, the certificate revocation request message and revoking the at least one digital certificate of the NF. 10 . A system for automatically binding a service-based interface (SBI) communications digital certificate lifecycle to a network function (NF) lifecycle, the system comprising: an NF repository function (NRF) including at least one processor and a memory; an NF register/deregister handler implemented by the at least one processor for receiving an NF deregister request message generated by an NF for deregistering the NF, wherein the NF is a 5G NF and the NF deregister request message is transmitted by the 5G NF for the 5G NF to indicate to the NRF that the 5G NF is decommissioning itself and that communications from the 5G NF should not appear in a 5G network; a certificate manager implemented by the at least one processor for generating, automatically in response to the NF deregister request message generated by the NF or successful completion of deregistration of the 5G NF in response to the NF deregister request message generated by the 5G NF, a certificate revocation request message for revoking at least one digital certificate used by the 5G NF for service-based interface (SBI) communications and transmitting, by the NRF, the certificate revocation request message to a certificate authority; wherein the NF register/deregister handler is configured to receive an NF register request message identifying the 5G NF; wherein the certificate manager is configured to determine that the at least digital one certificate of the 5G NF has been revoked; and wherein the NF register/deregister handler is configured to, in response to the determination that that the at least one digital certificate of the 5G NF has been revoked, perform a network security action in response to the NF register request message, wherein performing the network security action includes rejecting the NF register request message. 11 . The system of claim 10 wherein the certificate revocation request message includes an NF instance ID of the NF for revoking a digital certificate corresponding to the NF instance ID of the NF. 12 . The system of claim 11 wherein the NF instance ID is embedded in the digital certificate, which is included in the certificate revocation request message. 13 . The system of claim 10 wherein the certificate revocation request message includes a certificate management protocol (CMP) certificate revocation request message. 14 . The system of claim 10 wherein the certificate revocation request message includes a request message for revoking at least a transport layer security (TLS) certificate used by the NF for SBI communications. 15 . The system of claim 10 wherein the certificate revocation request message includes a request message for revoking at least an OAuth 2.0 certificate used by the NF for SBI communications. 16 . The system of claim 10 wherein the certificate revocation request message includes a request message for revoking at least a client credentials assertion (CCA) certificate used by the NF for SBI communications. 17 . The system of claim 10 wherein in determining that the at least one digital certificate has been revoked, the certificate manager is configured to query the certificate authority to determine the status of the at least one digital certificate. 18 . A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising: receiving, at a network function (NF) repository function (NRF), an NF deregister request message generated by an NF for deregistering the NF, wherein the NF is a 5G NF and the NF deregister request message is transmitted by the 5G NF for the 5G NF to indicate to the NRF that the 5G NF is decommissioning itself and that communications from the 5G NF should not appear in a 5G network; generating, by the NRF and automatically in response to the NF deregister request message generated by the 5G NF or successful completion of deregistration of the 5G NF in response to the NF deregister request message generated by the 5G NF, a certificate revocation request message for revoking at least one digital certificate used by the 5G NF for service-based interface (SBI) communications; transmitting, by the NRF, the certificate revocation req

Assignees

Inventors

Classifications

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12580905B2 cover?
A method for automatically binding an SBI communications digital certificate lifecycle to an NF lifecycle includes receiving, at an NRF, an NF deregister request message for deregistering an NF. The method further includes generating, by the NRF and in response to the NF deregister request message or successful completion of deregistration of the NF, a certificate revocation request message for…
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/0807. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 17 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).