US 12,010,510 B2
Systems and methods for secure virtualized base station orchestration
James J Ni, Medford, MA (US); Shanthakumar Ramakrishnan, Westford, MA (US); Tat Keung Chan, San Diego, CA (US); Alexander Medvinsky, San Diego, CA (US); Prashanth Venkatesh, Bangalore (IN); and Devaraj Sambandan, Bengaluru (IN)
Assigned to CommScope Technologies LLC, Claremont, NC (US)
Filed by CommScope Technologies LLC, Hickory, NC (US)
Filed on Jul. 1, 2022, as Appl. No. 17/856,164.
Claims priority of application No. 202141029723 (IN), filed on Jul. 2, 2021.
Prior Publication US 2023/0007474 A1, Jan. 5, 2023
Int. Cl. H04W 12/0431 (2021.01); H04L 9/40 (2022.01); H04W 12/069 (2021.01)
CPC H04W 12/0431 (2021.01) [H04L 63/0272 (2013.01); H04W 12/069 (2021.01)] 20 Claims
OG exemplary drawing
 
1. A method for secure virtualized wireless base station orchestration on a node of a scalable cloud environment, the method comprising:
obtaining a node certificate and a node private key from a global certificate authority (CA) using a first Public Key Infrastructure (PKI) request signed using a global certificate and a global private key, wherein the node certificate and the node private key defines a PKI signing certificate and a PKI signing private key;
establishing an orchestration access IPsec tunnel to an orchestration central cloud comprising one or more functions for edge cloud orchestration;
utilizing, via the orchestration access IPsec tunnel, the one or more functions for edge cloud orchestration to deploy on the node one or more virtualized entities comprising one or more virtual network functions of a wireless base station;
obtaining at least one virtual network function (VNF) certificate and at least one VNF private key for the deployed one or more virtualized entities from the global CA using at least one second PKI request signed using the global certificate and the global private key;
utilizing the at least one VNF certificate and the at least one VNF private key, establishing one or more IPsec tunnels comprising at least one of:
at least one X2 IPsec tunnel between the one or more virtual network functions of the wireless base station and a wireless network services operator network;
at least one S1/X2 IPsec tunnel between the one or more virtual network functions of the wireless base station and the wireless network services operator network;
at least one O1 IPsec tunnel to an Operations and Maintenance (OAM) secure gateway for a wireless base station Device Management System (DMS).