System and method for automatic onboarding of network functions to a credential vault

US2025077638A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2025077638-A1
Application numberUS-202218023216-A
CountryUS
Kind codeA1
Filing dateDec 21, 2022
Priority dateDec 21, 2022
Publication dateMar 6, 2025
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

To automatically onboard network functions to a credential vault, a orchestration processor actuates establishment of an cluster account for a network cluster, and actuates a cluster configuration of a processor of the vault to enable authentication of a network cluster. For each of a plurality of network functions associated with the network cluster, the orchestration processor generates an identifier, sets values for parameters of an initialization parameter set, actuates assignment of access permissions for a code address on a memory of the vault, actuates assignment of elevated access permissions for a credential address on the vault memory, and actuates association of the network function with a cluster account of the network cluster. The vault memory thereby defines credential addresses each corresponding to a respective network function.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for onboarding of network functions to a credential vault, the credential vault including a vault memory and a vault processor, the vault memory storing an authentication code at a code address thereof, the method comprising, by at least one processor: actuating establishment of an cluster account for a network cluster; actuating a cluster configuration of the vault processor to enable authentication of the network cluster; and for each network function of a plurality of network functions associated with the network cluster: generating an identifier for the network function, setting values for parameters of an initialization parameter set for the network function, the initialization parameter set including a credential address in the vault memory for storage of a credential for the network function, a value of the credential address being based on the generated identifier for the network function, actuating assignment of access permissions to the network function for the code address on the vault memory, actuating assignment of elevated access permissions to the network function for the credential address on the vault memory, and actuating association of the network function with the cluster account of the network cluster; the vault memory thereby defining a plurality of credential addresses each corresponding to a respective one of the plurality of network functions, wherein the vault processor is configured to: provide, based on receipt of a code retrieval request identifying the code address from a device having access permissions thereto, the authentication code, store at a selected credential address, based on receipt of a credential storage request providing a credential and identifying the selected credential address from a device having elevated access permissions thereto, the provided credential, and provide, based on receipt of a credential retrieval request identifying the selected credential address from a device having elevated access permissions thereto, the credential stored at the selected credential address. 2 . The method of claim 1 , wherein the initialization parameter set further includes an identifier for the associated cluster, an account identifier of the network function for the associated cluster, an account identifier of the network function for the credential vault, and the code address in the vault memory. 3 . The method of claim 2 , wherein the values for the account identifier of the network function for the associated cluster and the account identifier of the network function for the credential vault are based on the generated identifier for the network function. 4 . The method of claim 1 , wherein the identifier for the network function is generated based on a concatenation of values reflecting features of the network function. 5 . The method of claim 1 , wherein an authentication processor is configured to provide, based on receipt of a signature request including the authentication code, a signed authentication certificate, and wherein the credential includes a private key and the signed authentication certificate. 6 . The method of claim 5 , wherein the cluster configuration of the vault processor includes establishing access of an authentication token for the network cluster to the vault processor, and wherein the signature request further includes the authentication token for the network cluster. 7 . A non-transitory computer-readable recording medium having recorded thereon instructions executable by at least one processor to perform a method for onboarding of network functions to a credential vault, the credential vault comprising a vault memory and a vault processor, the vault memory storing an authentication code at a code address thereof, the method comprising: actuating establishment of an cluster account for a network cluster; actuating a cluster configuration of the vault processor to enable authentication of the network cluster; and for each network function of a plurality of network functions associated with the network cluster: generating an identifier for the network function, setting values for parameters of an initialization parameter set for the network function, the initialization parameter set including a credential address in the vault memory for storage of a credential for the network function, a value of the credential address being based on the generated identifier for the network function, actuating assignment of access permissions to the network function for the code address on the vault memory, actuating assignment of elevated access permissions to the network function for the credential address on the vault memory, and actuating association of the network function with the cluster account of the network cluster; the vault memory thereby defining a plurality of credential addresses each corresponding to a respective one of the plurality of network functions, wherein the vault processor is configured to: provide, based on receipt of a code retrieval request identifying the code address from a device having access permissions thereto, the authentication code, store at a selected credential address, based on receipt of a credential storage request providing a credential and identifying the selected credential address from a device having elevated access permissions thereto, the provided credential, and provide, based on receipt of a credential retrieval request identifying the selected credential address from a device having elevated access permissions thereto, the credential stored at the selected credential address. 8 . The recording medium of claim 7 , wherein the initialization parameter set further includes an identifier for the associated cluster, an account identifier of the network function for the associated cluster, an account identifier of the network function for the credential vault, and the code address in the vault memory. 9 . The recording medium of claim 8 , wherein the values for the account identifier of the network function for the associated cluster and the account identifier of the network function for the credential vault are based on the generated identifier for the network function. 10 . The recording medium of claim 7 , wherein the identifier for the network function is generated based on a concatenation of values reflecting features of the network function. 11 . The recording medium of claim 7 , wherein an authentication processor is configured to provide, based on receipt of a signature request including the authentication code, a signed authentication certificate, and wherein the credential includes a private key and the signed authentication certificate. 12 . The recording medium of claim 11 , wherein the cluster configuration of the vault processor includes establishing access of an authentication token for the network cluster to the vault processor, and wherein the signature request further includes the authentication token for the network cluster. 13 . A system for onboarding of network functions to a credential vault, the system comprising: an orchestrator, comprising at least one orchestration processor; and the credential vault, comprising a vault memory and at least one vault processor, wherein the vault memory stores an authentication code at a code address thereof, wherein the at least one orchestration processor is configured to: actuate establishment of an cluster account for a network cluster; actuate a cluster configuration of the at least one vault processor to enable authentication of the network cluster; and for each network function of a p

Assignees

Inventors

Classifications

  • involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements (network architectures or network communication protocols for supporting authentication of entities using certificates in a packet data network H04L63/0823) · CPC title

  • involving digital signatures · CPC title

  • using tickets or tokens, e.g. Kerberos (network architectures or network communication protocols for entities authentication using tickets in a packet data network H04L63/0807) · CPC title

  • Access rights, e.g. capability lists, access control lists, access tables, access matrices · CPC title

  • G06F21/44Primary

    Program or device authentication · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2025077638A1 cover?
To automatically onboard network functions to a credential vault, a orchestration processor actuates establishment of an cluster account for a network cluster, and actuates a cluster configuration of a processor of the vault to enable authentication of a network cluster. For each of a plurality of network functions associated with the network cluster, the orchestration processor generates an id…
Who is the assignee on this patent?
Rakuten Symphony Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/44. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Mar 06 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).