US 11,870,768 B1
Certificate-based techniques to securely onboard a radio interface unit
Devendra Kumar Vishwakarma, North Chelmsford, MA (US); Om Prakash Suthar, Bolingbrook, IL (US); and Vivek Agarwal, Chelmsford, MA (US)
Assigned to CISCO TECHNOLOGY, INC., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Apr. 10, 2020, as Appl. No. 16/845,531.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04W 84/14 (2009.01); H04W 12/08 (2021.01); H04W 8/26 (2009.01); H04W 12/069 (2021.01); H04W 12/71 (2021.01); H04L 61/5014 (2022.01); H04L 101/622 (2022.01); H04L 101/659 (2022.01)
CPC H04L 63/0823 (2013.01) [H04L 61/5014 (2022.05); H04L 63/0876 (2013.01); H04W 8/26 (2013.01); H04W 12/069 (2021.01); H04W 12/08 (2013.01); H04W 12/71 (2021.01); H04W 84/14 (2013.01); H04L 2101/622 (2022.05); H04L 2101/659 (2022.05)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
obtaining, by a Dynamic Host Configuration Protocol (DHCP) server, an address assignment request for a radio interface unit (RIU) of a Remote Radio Head (RRH) that interfaces, via a top-of-rack switch, with a virtualized distributed unit (vDU) of a virtualized Radio Access Network (vRAN), wherein the address assignment request comprises a vendor device certificate, a signed nonce, a non-encrypted serial number for the RIU, a signed serial number for the RIU, and a vendor identifier identifying a vendor or manufacturer of the RIU;
validating the vendor device certificate, the signed nonce, and the signed serial number for the RIU by the DHCP server based, at least in part, on a vendor root certification authority certificate;
validating the non-encrypted serial number for the RIU;
generating an address assignment response by the DHCP server based on validating the non-encrypted serial number for the RIU, the vendor device certificate, the signed nonce, and the signed serial number for the RIU, wherein the address assignment response comprises an Internet Protocol version 6 (IPv6) address for the RIU, a service provider root certification authority certificate, and a Fully Qualified Domain Name (FQDN) for a service provider certification authority entity; and
transmitting the address assignment response toward the RIU by the DHCP server.