US 12,238,521 B2
Enhanced authentication procedure for O-RAN network elements
Francesca Rivera, Tokyo (JP); Raghavendran Ramiya, Bengaluru (IN); and Ritesh Kumar Kalle, Tokyo (JP)
Assigned to RAKUTEN MOBILE, INC., Tokyo (JP)
Appl. No. 17/799,121
Filed by RAKUTEN MOBILE, INC., Tokyo (JP)
PCT Filed Apr. 13, 2022, PCT No. PCT/US2022/024597
§ 371(c)(1), (2) Date Aug. 11, 2022,
PCT Pub. No. WO2023/154071, PCT Pub. Date Aug. 17, 2023.
Claims priority of provisional application 63/318,898, filed on Mar. 11, 2022.
Claims priority of provisional application 63/309,877, filed on Feb. 14, 2022.
Prior Publication US 2024/0187858 A1, Jun. 6, 2024
Int. Cl. H04W 12/069 (2021.01); H04L 61/5014 (2022.01)
CPC H04W 12/069 (2021.01) [H04L 61/5014 (2022.05)] 20 Claims
OG exemplary drawing
 
1. A system for performing an enhanced authentication procedure in a mobile communications network, the system comprising:
a first network element with IEEE 802.1x support;
a second network element without IEEE 802.1x support;
a storage device configured to store authentication capabilities of network elements in the mobile communications network;
a switch configured to obtain device information from the first network element and the second network element, and to transmit the obtained device information to the storage device in order to determine whether each of the first network element and the second network element supports IEEE 802.1x authentication;
a first authentication server configured to perform authentication in accordance with IEEE 802.1x;
at least one server configured to perform Dynamic Host Configuration Protocol (DHCP) authentication; and
an operator certificate authority configured to enroll certificates for network elements in the mobile communication network,
wherein the first network element is configured to initiate the IEEE 802.1x authentication with the switch based on the switch determining that the first network element supports the IEEE 802.1x authentication, the first authentication server is configured to authenticate the first network element, and the first network element is configured to enroll a certificate with the operator certificate authority based on a successful authentication, and
wherein the second network element is configured to initiate a DHCP authentication with the at least one server configured to perform DHCP authentication based on the switch determining that that the second network element does not support the IEEE 802.1x authentication, to obtain information on the operator certificate authority from the at least one server upon authentication, and to enroll a certificate with the operator certificate authority based on the obtained information on the operator certificate authority.