Policy-based mechanism for managing access to sensitive boot data in O-Cloud

By implementing a policy-based data management approach in the O-RAN cloud infrastructure, the issues of secure data erasure and intrusion warnings during the bootstrapping of NF microservices were resolved, thereby improving secure data processing and network defense.

CN121100516APending Publication Date: 2025-12-09RAKUTEN SYMPHONY INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380098213.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-05-12
Filing Date
2023-11-24
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

In existing technologies, O-RAN cloud infrastructure lacks a policy-based mechanism to erase or unload sensitive data during the bootstrapping process of NF microservices, leading to potential security risks and an increased attack surface, while also lacking a warning mechanism for potential intrusions.

Method used

This paper provides a policy-based data management method and system that stores and enforces data policies through O-Cloud infrastructure, including unmounting, remounting, and security threat notification actions, to ensure the secure handling of sensitive data during the NF boot process.

Benefits of technology

It enables secure handling of sensitive data during NF booting, reduces the network's attack surface, and promptly notifies NF to take defensive measures, thereby improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121100516A_ABST
    Figure CN121100516A_ABST
Patent Text Reader

Abstract

A method, system, and apparatus are provided for policy-based data management in an open radio access network (O-RAN) cloud (O-Cloud) infrastructure. The method may include storing, by an O-Cloud infrastructure, a data policy for managing a network function (NF) deployed on the O-Cloud infrastructure, the data policy including a definition for at least one action from among: an offload action, a remount action, and a notification action for notifying the NF of a security threat with respect to a data volume; and performing, by the O-Cloud infrastructure, the at least one action based on the data policy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Systems and methods consistent with exemplary embodiments of this disclosure generally relate to policy-based mechanisms for managing access to sensitive boot data, specifically in relation to Open Radio Access Network (O-RAN) Cloud (O-Cloud). Background Technology

[0002] Radio Access Networks (RANs) are critical components of telecommunications systems because they connect end-user equipment (or user equipment) to other parts of the network. A RAN comprises a combination of various network elements (NEs) that connect end-user equipment to the core network. Traditionally, the hardware and / or software for a particular RAN are vendor-specific.

[0003] Open RAN (O-RAN) technology has emerged, enabling multiple vendors to provide hardware and / or software to telecommunications systems. To this end, O-RAN decomposes RAN functions into Centralized Units (CUs), Distributed Units (DUs), and Radio Units (RUs). A CU is a logical node that carries the RAN's Radio Resource Control (RRC) sublayer, Serving Data Adaptation Protocol (SDAP) sublayer, and / or Packet Data Convergence Protocol (PDCP) sublayer. A DU is a logical node that carries the RAN's Radio Link Control (RLC) sublayer, Media Access Control (MAC) sublayer, and Physical (PHY) sublayer. An RU is a physical node that converts radio signals from antennas into digital signals that can be transmitted to the DU via fronthaul. Because these entities have open protocols and interfaces with each other, they can be developed by different vendors.

[0004] Figure 1 The diagram illustrates the O-RAN architecture of the relevant technologies. (Reference) Figure 1 In the O-RAN architecture, RAN functions are controlled and optimized by RICs. RICs are software-defined components that enable modular applications to facilitate the multi-vendor operability required in O-RAN systems, as well as to automate and optimize RAN operations. RICs are classified into two types: Non-Real-Time RICs (Non-RTRICs) and Near-Real-Time RICs (Near-RT RICs).

[0005] Non-RT RICs are control points in non-real-time control loops and operate on timescales greater than 1 second within the Service Management and Orchestration (SMO) framework. Their functionality is implemented through modular applications called rApps (rApp 1, ..., rApp N), and includes: providing policy-based guidance and enrichment across the A1 interface, which enables direct communication between the Non-RT RIC and Near-RT RICs; performing data analysis; AI / ML training and inference for RAN optimization; and / or suggesting configuration management actions via the O1 interface, which connects the SMO to RAN-managed elements such as Near-RT RICs, O-RAN Centralized Units (O-CUs), O-RAN Distributed Units (O-DUs), etc.

[0006] Near-RT RIC operates on a timescale between 10 milliseconds and 1 second and connects via E2 interfaces to O-DU, O-CU (disassembled into O-CU control plane (O-CU-CP) and O-CU user plane (O-CU-UP)), and Open Evolution NodeB (O-eNB). Near-RT RIC uses the E2 interface to control the underlying RAN elements (E2 nodes / network functions (NFs)) through a near real-time control loop. Near-RT RIC monitors, aborts / stops, covers, and controls E2 nodes (O-CU, O-DU, and O-eNB) through policies. For example, Near-RT sets policy parameters on the functions activated by E2 nodes. Furthermore, Near-RT RIC carries xApps to implement functions such as Quality of Service (QoS) optimization, mobility optimization, slicing optimization, interference mitigation, load balancing, and security. Both types of RICs collaborate to optimize the O-RAN. For example, the Non-RT RIC provides policies, data, and AI / ML models for RAN optimization executed and used by the Near-RT RIC through the A1 interface, and Near-RT returns policy feedback (i.e., how well the policies set by the Non-RT RIC are working).

[0007] The SMO framework (with the Non-RT RIC residing within it) manages and orchestrates RAN elements. Specifically, the SMO includes the Federated O-Cloud Orchestration and Management (FOCOM), the Network Function Orchestrator (NFO) which manages Virtual Network Functions (VNFs) based on Virtual Machines (VMs) and VNFs (CNFs) based on Containers (i.e., instances), and the OAM, which manages and orchestrates what is known as the O-RAN Cloud (O-Cloud). The O-Cloud is a collection of physical RAN nodes that host the RIC, O-CU, and O-DU, supporting software components (e.g., operating system and runtime environment), and the SMO itself. In other words, the SMO manages the O-Cloud internally. The O2 interface is the interface between the SMO and its O-Cloud. Through the O2 interface, the SMO provides Infrastructure Management Services (IMS) and Deployment Management Services (DMS). The O2 interface can also send O2 telemetry data to the SMO, such as O-Cloud configuration or any logical function data, energy consumption, node health status, etc. Summary of the Invention

[0008] In related technologies, a Network Function (NF), which can be implemented as a Virtual Network Function (VNF) or a CNF, operates as a microservice that requires inherently sensitive data (e.g., private keys, access tokens, passwords, and configuration data). During the bootstrapping of such an NF, the data can be provided by a microservice runtime engine (e.g., O-Cloud's VNF / CNF runtime engine, which may be referred to as the "O-Cloud runtime engine" below) by mounting the data as a virtual storage drive within the microservice.

[0009] Therefore, an NF running as a microservice during bootstrapping can use data from a virtual drive according to programmed logic. However, systems using this technology lack any policy-based mechanisms for erasing or offloading sensitive data from the NF microservice. Consequently, any sensitive data that may remain in the existing NF service after use could pose a security risk to the entire network by increasing the NF's attack surface.

[0010] Furthermore, the systems based on these technologies lack any method to warn NFs of potential intrusions into the O-Cloud, enabling NFs to take preventative actions to improve their security and reduce the attack surface. Therefore, a policy-based approach is needed to securely manage data volumes related to NFs and provide them with notifications.

[0011] This disclosure provides an example embodiment of a method and system for policy-based data management in an Open Radio Access Network (O-RAN) cloud (O-Cloud) infrastructure. Specifically, the method may include: storing, by the O-Cloud infrastructure, a data policy for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policy including definitions for at least one action regarding a data volume, namely: an unmount action, a remount action, and a notification action for notifying the NF of a security threat; and having the O-Cloud infrastructure perform the at least one action based on the data policy. Therefore, the embodiments may allow sensitive data involved in the booting of NFs to be securely processed in a policy-based manner, and NFs may receive notifications that can be used to proactively reduce their attack surface.

[0012] According to an embodiment, an apparatus for policy-based management of an Open Radio Access Network (O-RAN) Cloud (O-Cloud) infrastructure can be provided, wherein the apparatus is configured to: store data policies for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policies including definitions for at least one action regarding a data volume from the following actions: an unmount action, a remount action, and a notification action for notifying the NF of a security threat; and have the O-Cloud infrastructure perform the at least one action based on the data policies.

[0013] According to an embodiment, a non-transitory computer-readable recording medium may be provided having instructions recorded thereon to perform a method comprising: storing, by an O-Cloud infrastructure, a data policy for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policy including definitions of at least one action for a data volume from the following actions: an unmount action, a remount action, and a notification action for notifying the NF of a security threat; and having the O-Cloud infrastructure perform the at least one action based on the data policy.

[0014] Other aspects will be set forth in the description which follows, and some will be apparent from the description or may be implemented by practicing the embodiments presented in this disclosure. Attached Figure Description

[0015] Features, aspects, and advantages of certain exemplary embodiments of this disclosure will be described below with reference to the accompanying drawings, wherein like reference numerals denote like elements, and in the drawings:

[0016] Figure 1 The diagram illustrates the O-RAN structure based on related technologies;

[0017] Figure 2 The diagram illustrates a system architecture according to an embodiment;

[0018] Figure 3 The illustration shows a flowchart of a method for managing a data volume according to an embodiment;

[0019] Figure 4 The illustration shows an example environment in which the systems and / or methods described herein can be implemented; and

[0020] Figure 5 The illustration shows an example component of a device according to an embodiment. Detailed Implementation

[0021] The following detailed description of the example embodiments is taken with reference to the accompanying drawings. The same reference numerals in different drawings may identify the same or similar elements.

[0022] The foregoing disclosure provides illustrations and descriptions, but is not intended to be exhaustive or to limit the implementation to the exact forms disclosed. Modifications and variations may be made based on the foregoing disclosure or through practice of the implementation. Furthermore, one or more features or components of one embodiment may be incorporated into or combined with another embodiment (or one or more features of another embodiment). Additionally, in the flowcharts and descriptions of operations provided below, it will be understood that one or more operations may be omitted, one or more operations may be added, one or more operations may be performed (at least partially) simultaneously, and the order of one or more operations may be changed.

[0023] It is evident that the systems and / or methods described herein can be implemented using various forms of hardware, firmware, or a combination of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods is not a limitation on the implementation. Therefore, no specific software code is referenced in the description of the operation and behavior of the systems and / or methods herein. It is understood that software and hardware can be designed based on the descriptions herein to implement the systems and / or methods.

[0024] Although specific combinations of features are detailed in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of possible embodiments. In fact, many of these features can be combined in ways not specifically detailed in the claims and / or disclosed in the specification. While each dependent claim listed below may directly refer to only one claim, the disclosure of possible embodiments includes combinations of each dependent claim with all other claims in the claim set.

[0025] Unless explicitly stated otherwise, elements, actions, or instructions used herein should not be construed as critical or necessary. Furthermore, as used herein, the article “a” is intended to include one or more items and may be used interchangeably with “one or more.” The term “single” or similar language is used where only a single item is referred to. Additionally, terms such as “having,” “including,” etc., as used herein, are intended to express open-ended terms. Furthermore, unless explicitly stated otherwise, the phrase “based on” is intended to mean “at least partially based on.” Furthermore, expressions such as “at least one of [A] and [B]” or “at least one of [A] or [B]” should be understood to include only A, only B, or both A and B.

[0026] This disclosure provides an example embodiment of a method and system for policy-based data management in an Open Radio Access Network (O-RAN) cloud (O-Cloud) infrastructure. Specifically, the method may include: storing, by the O-Cloud infrastructure, a data policy for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policy including definitions for at least one action regarding a data volume, namely: an unmount action, a remount action, and a notification action for notifying the NF of a security threat; and having the O-Cloud infrastructure perform the at least one action based on the data policy. Therefore, the embodiments may allow sensitive data involved in the booting of NFs to be securely processed in a policy-based manner, and NFs may receive notifications that can be used to proactively reduce their attack surface.

[0027] Figure 2 The figure illustrates a system architecture diagram of system 200 according to an embodiment.

[0028] refer to Figure 2 Multiple Virtual Network Functions (VNFs) 210 (VNF-1 210-1, VNF-2 210-2, ... VNF-N 210-N) and container-based VNFs (CNFs) 220 (CNF-1 220-1, CNF-2 220-2, ... CNF-N 220-N) can be provided in system 200. VNFs 210 and CNFs 220 can receive threat level notifications from the O-Cloud runtime engine 230.

[0029] The O-Cloud runtime engine 230 can be responsible for managing VNFs / CNFs (i.e., each of VNF 210 and CNF 220). According to some embodiments, it can be a dedicated runtime engine solely for managing VNFs / CNFs, or it may include functionality for handling other operations, depending on the specific implementation. The O-Cloud runtime engine 230 can run within the O-Cloud infrastructure. The O-Cloud runtime engine 230 can provide the runtime environment required by VNF 210 and CNF 220, including mounting sensitive data volumes as files or environment variables in the file system during boot.

[0030] The O-Cloud runtime engine 230 may include a VNF policy store 231 and a CNF policy store 232, which may be used to store policies related to processing data volumes associated with VNF 210 and CNF 220, respectively. According to embodiments, these policies may specifically relate to processing sensitive data.

[0031] According to an embodiment, a VNF / CNF policy (which may also be referred to below as an "NF policy") may contain rules instructing how sensitive data should be handled. These rules may define actions that can be performed on each VNF / CNF, including, but not limited to, unmounting, remounting, and notifying the VNF / CNF for sensitive data management.

[0032] For example, the NF policy used for unloading actions can define rules and / or criteria that can be used to unload a specific data volume (which may have been previously unloaded by the O-Cloud runtime engine 230).

[0033] According to some embodiments, the policy may include rules for time-based unloading actions, wherein the time-based unloading rules can be used to unload the virtual data volume after a predefined period of time, or to restore the environment variables of a specific virtual data volume. Therefore, VNF 210 and CNF 220 can have ample time during boot to read the necessary information from the data volume and any environment variables, and the data volume will subsequently be unloaded based on the time-based rules.

[0034] According to some embodiments, the policy may include rules for offloading actions, which may include interactive shell rules, wherein the offloading and / or recovery actions may be performed by O-Cloud (e.g., an operator) as a preparatory step before the interactive shell requests for VNF 210 and CNF 220 are fulfilled.

[0035] According to some embodiments, the strategy may include rules based on NF state (e.g., which may be determined as the result of an activity probe) as criteria for performing unloading actions.

[0036] According to some implementations, a policy may include rules / actions, where an NF may call a specific O-Cloud API to request an offload action.

[0037] According to some embodiments, any custom criteria can be defined as placeholder rules that can be customized during deployment (using well-defined syntax) to include any custom logic for performing the unloading operation. As a non-limiting example, custom criteria can be defined based on the presence of a specific file in the file system. As another example, a threat-searching script can indicate the presence of a high-level threat and can also be used as a criterion for unloading a volume.

[0038] It should be understood that, depending on the specific implementation, the list of rules for the unloading action of the strategy described above may be executed simultaneously or mutually exclusively, and other rules and / or guidelines not mentioned may also be executed.

[0039] Conversely, remount actions can be performed by the O-Cloud runtime engine 230 based on policies. These can include remount actions that define rules / guidelines for remounting specific data volumes that were previously unmounted by the O-Cloud runtime engine 230.

[0040] According to some embodiments, the remount rule can be simply defined as whether to allow remounting of a previously unmounted volume.

[0041] According to some implementations, a policy may include rules / actions, where an NF may call a specific O-Cloud API to request a remount action.

[0042] According to some embodiments, any custom criteria can be defined as placeholder rules that can be customized during deployment (using well-defined syntax) to include any custom logic for performing remount operations. As a non-limiting example, custom criteria can be defined based on the presence of a specific file in the file system. As another example, a threat-searching script can indicate the presence of a low-level threat and can also be used as a criterion for remounting a volume.

[0043] It should be understood that, depending on the specific implementation, the list of rules for remounting actions of the above policy can be executed simultaneously or mutually exclusively, and other rules and / or guidelines not mentioned may also be executed.

[0044] Rules for sending notifications to specific VNFs / CNFs can also be defined in the policy, and these notifications can be configured on a per-NF and / or per-data-volume basis. Specifically, these notifications can indicate the security level of a perceived dynamic threat detected (directly or indirectly) by the O-cloud runtime engine 230. According to some embodiments, based on receiving such a notification, VNF 210 and / or CNF 220 can take appropriate action to defend themselves and reduce the attack surface in response to a high perceived threat level. By way of non-limiting examples, VNFs / CNFs can remove sensitive data from their memory / cache and retrieve information from secure storage only on demand. It should be understood that, depending on the specific implementation, other security actions may be taken by VNF 210 and / or CNF 220.

[0045] Figure 3 The illustration shows a flowchart of a method for managing data volumes according to an embodiment.

[0046] At Operation 301, the O-Cloud infrastructure can store information for managing network functions (NFs) deployed on the O-Cloud infrastructure (e.g., see above reference). Figure 2 The data policy (either of VNF 210 and / or CNF 220). According to embodiments, the data policy may define rules for controlling how sensitive data in a data volume is handled. According to some embodiments, the data volume may specifically be a sensitive data volume. The data policy may include the definition of at least one of the following actions: unmounting action, remounting action, and notification action for notifying the NF of a security threat.

[0047] As an example, for an unloading action, the definition may include at least one of the following: a time-based unloading rule that defines the time at which the unloading action is performed; an interactive shell rule that defines whether the unloading action is performed before the interactive shell request to the NF is fulfilled; an NF state rule that indicates whether the state of the NF will be considered for the execution of the unloading action; and an NF request rule that indicates whether the unloading action is requestable by the NF.

[0048] As another example, for a remount action, the definition may include at least one of the following: an allow rule that defines whether the remount action is permitted for a previously unmounted data volume; and an NF request rule that indicates whether the remount action is requestable by an NF.

[0049] As another example, for notification actions, this definition can indicate whether security notifications for data volumes are enabled, and that the security notification indicates the perceived dynamic threat level from the O-Cloud infrastructure to the NF.

[0050] It should be understood that Operation 301 can be more specifically determined by the O-Cloud runtime engine (e.g., see the reference above). Figure 2 The O-Cloud runtime engine 230 executes the data policies. Data policies can be stored in a policy store located in the O-Cloud runtime engine (e.g., VNF policy store 231 and / or CNF policy store 232). The O-Cloud infrastructure can store multiple data policies on a per NF basis. Data policies can also define at least one of the aforementioned actions for multiple data volumes that mount sensitive data to an NF (e.g., it can be applied to more than one data volume).

[0051] At operation 302, the O-Cloud infrastructure can perform at least one of the aforementioned actions based on a data policy. It should be understood that operation 302 can be more specifically defined by the O-Cloud runtime engine (e.g., as referenced above). Figure 2 The O-Cloud runtime engine 230 is executed.

[0052] Based on the above, it is understood that the example implementation may allow sensitive data involved in the bootstrapping of the NF to be handled securely in a policy-based manner, and the NF may receive notifications that can be used to preemptively reduce its attack surface.

[0053] Figure 4 This is a diagram illustrating an example environment 400 in which the systems and / or methods described herein can be implemented. (See diagram 400 for example.) Figure 4 As shown, environment 400 may include user equipment 410, platform 420, and network 430. Devices in environment 400 may be interconnected via wired connections, wireless connections, or a combination of wired and wireless connections. In embodiments, references above... Figures 2 to 4 Any functions and operations described herein can be provided by Figure 4 The elements shown in the diagram can be executed in any combination.

[0054] User equipment 410 includes one or more devices capable of receiving, generating, storing, processing, and / or providing information associated with platform 420. For example, user equipment 410 may include computing devices (e.g., desktop computers, laptop computers, tablet computers, handheld computers, smart speakers, servers, etc.), mobile phones (e.g., smartphones, cordless phones, etc.), wearable devices (e.g., smart glasses, or smartwatches), or similar devices. In some embodiments, user equipment 410 can receive information from platform 420 and / or send information to platform 420.

[0055] Platform 420 includes one or more devices capable of receiving, generating, storing, processing, and / or providing information. In some implementations, platform 420 may include a cloud server or a group of cloud servers. In some embodiments, platform 420 may be designed to be modular, allowing certain software components to be switched in or out as needed. Thus, platform 420 can be easily and / or quickly reconfigured for different uses.

[0056] As shown in some embodiments, platform 420 may be hosted in a cloud computing environment 422. It is worth noting that although the embodiments described herein describe platform 420 as being hosted in a cloud computing environment 422, in some implementations, platform 420 may not be cloud-based (i.e., may be implemented outside of a cloud computing environment) or may be partially cloud-based.

[0057] The cloud computing environment 422 includes the environment of the hosting platform 420. The cloud computing environment 422 can provide services such as computing, software, data access, and storage, without requiring end users (e.g., user equipment 410) to be aware of the physical location and configuration of the system and / or equipment of the hosting platform 420. As shown in the figure, the cloud computing environment 422 may contain a set of computing resources 424 (collectively referred to as "computing resources 424," and individually referred to as "computing resources 424").

[0058] Computing resource 424 includes one or more personal computers, computing device clusters, workstation computers, server devices, or other types of computing and / or communication devices. In some embodiments, computing resource 424 may host platform 420. Cloud resources may include computing instances executed in computing resource 424, storage devices provided in computing resource 424, data transmission devices provided by computing resource 424, etc. In some embodiments, computing resource 424 may communicate with other computing resources 424 via wired connections, wireless connections, or a combination of wired and wireless connections.

[0059] like Figure 4As further illustrated, computing resources 424 include a set of cloud resources, such as one or more applications (“APPs”) 424-1, one or more virtual machines (“VMs”) 424-2, virtualized storage (“VSs”) 424-3, one or more hypervisors (“HYPs”) 424-4, etc. While the current example embodiment refers to virtualized network functionality, it will be understood that one or more other embodiments are not limited thereto and may be implemented in at least one of containers, cloud-native services, one or more container platforms, etc. For example, in one or more other example embodiments, any component of the components described above (e.g., nodes, E2 nodes, SMO functionality, RIC, systems, devices, etc.) may be a software-based component deployed or hosted, for example, in a server cluster such as a hybrid cloud server, data center server, and the like. The software-based component may be containerized and may be deployed and controlled by one or more machines (referred to as “nodes”) that run or execute containerized network elements and are addressable. In this respect, the server cluster may include at least one master node and multiple worker nodes, wherein the master node controls and manages a set of associated worker nodes.

[0060] Application 424-1 includes one or more software applications that can be provided to or accessed by user equipment 410. Application 424-1 can eliminate the need to install and execute software applications on user equipment 410. For example, application 424-1 may include platform-associated software and / or any other software that can be provided via cloud computing environment 422. In some implementations, an application 424-1 may send information to or receive information from one or more other applications 424-1 via virtual machine 424-2.

[0061] Virtual machine 424-2 comprises a software-implemented machine (e.g., a computer) that executes programs like a physical machine. Depending on the purpose of virtual machine 424-2 and its correspondence to any real machine, virtual machine 424-2 can be a system virtual machine or a process virtual machine. A system virtual machine can provide a complete system platform that supports the execution of a complete operating system (“OS”). A process virtual machine can execute a single program and can support a single process. In some implementations, virtual machine 424-2 can execute on behalf of a user (e.g., user device 410) and can manage the infrastructure of cloud computing environment 422, such as data management, synchronization, or long-duration data transfer.

[0062] Virtualized storage 424-3 includes one or more storage systems and / or one or more devices that utilize virtualization technology within the storage system or device of computing resource 424. In some implementations, the type of virtualization within the storage system environment may include block virtualization and file virtualization. Block virtualization may refer to abstracting (or separating) logical storage from physical storage, allowing the storage system to be accessed without concern for physical storage or heterogeneous architectures. Separation provides storage system administrators with flexibility in how they manage end-user storage. File virtualization can eliminate the dependency between data accessed at the file level and the location where the files are physically stored. This can enable performance optimization for storage usage, server consolidation, and / or non-disruptive file migration.

[0063] Hypervisor 424-4 can provide hardware virtualization technology that allows multiple operating systems (e.g., "guest operating systems") to execute concurrently on a host computer (such as computing resource 424). Hypervisor 424-4 can present a virtual operating platform to the guest operating system and manage the execution of the guest operating system. Multiple instances of various operating systems can share virtualized hardware resources.

[0064] Network 430 includes one or more wired and / or wireless networks. For example, network 430 may include cellular networks (e.g., fifth-generation (5G) networks, long-term evolution (LTE) networks, third-generation (3G) networks, code division multiple access (CDMA) networks, etc.), public land mobile networks (PLMN), local area networks (LAN), wide area networks (WAN), metropolitan area networks (MAN), telephone networks (e.g., public switched telephone network (PSTN)), private networks, ad hoc networks, intranets, the Internet, fiber-optic networks, etc., and / or combinations of these or other types of networks.

[0065] Figure 4 The number and arrangement of devices and networks shown are provided as examples. In practice, there may be different arrangements. Figure 4 The examples shown are those that, compared to additional equipment and / or networks, fewer equipment and / or networks, different equipment and / or networks, or differently arranged equipment and / or networks. Furthermore, Figure 4 The two or more devices shown can be implemented within a single device, or Figure 4 The single device shown can be implemented as multiple distributed devices. Additionally or alternatively, a group of devices in environment 400 (e.g., one or more devices) can perform one or more functions described as being performed by another group of devices in environment 400.

[0066] Figure 5This is a diagram illustrating example components of device 500. Device 500 may correspond to user device 410 and / or platform 420. Figure 5 As shown, device 500 may include bus 510, processor 520, memory 530, storage component 540, input component 550, output component 560, and communication interface 570.

[0067] Bus 510 includes components that allow communication between components of device 500. Processor 520 may be implemented in hardware, firmware, or a combination of hardware and software. Processor 520 may be a central processing unit (CPU), graphics processing unit (GPU), accelerated processing unit (APU), microprocessor, microcontroller, digital signal processor, field-programmable gate array (FPGA), application-specific integrated circuit (ASIC), or another type of processing component. In some embodiments, processor 520 includes one or more processors that can be programmed to perform functions. Memory 530 includes random access memory (RAM), read-only memory (ROM), and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, and / or optical memory) storing information and / or instructions used by processor 520.

[0068] Storage component 540 stores information and / or software related to the operation and use of device 500. For example, storage component 540 may include a hard disk (e.g., magnetic disk, optical disk, magneto-optical disk, and / or solid-state drive), optical disk (CD), digital versatile disk (DVD), floppy disk, cassette tape, magnetic tape, and / or another type of non-transitory computer-readable medium, and a corresponding drive. Input component 550 includes components that allow device 500 to receive information, such as via user input (e.g., touchscreen display, keyboard, keypad, mouse, buttons, switches, and / or microphone). Additionally or optionally, input component 550 may include sensors for sensing information (e.g., a Global Positioning System (GPS) component, accelerometer, gyroscope, and / or actuator). Output component 560 includes components that provide output information from device 500 (e.g., a display, speaker, and / or one or more light-emitting diodes (LEDs)).

[0069] Communication interface 570 includes transceiver-like components (e.g., transceiver and / or separate receiver and transmitter) that enable device 500 to communicate with other devices, such as via wired connection, wireless connection, or a combination of wired and wireless connection. Communication interface 570 may allow device 500 to receive information from and / or provide information to another device. For example, communication interface 570 may include an Ethernet interface, optical interface, coaxial interface, infrared interface, radio frequency (RF) interface, universal serial bus (USB) interface, Wi-Fi interface, cellular network interface, etc.

[0070] Device 500 can perform one or more of the processes described herein. Device 500 can perform these processes in response to processor 520 executing software instructions stored in a non-transitory computer-readable medium, such as memory 530 and / or storage component 540. Computer-readable medium is defined herein as a non-transitory memory device. Memory devices include memory space within a single physical storage device or memory space distributed across multiple physical storage devices.

[0071] Software instructions may be read into memory 530 and / or storage component 540 via communication interface 570 from another computer-readable medium or from another device. During execution, the software instructions stored in memory 530 and / or storage component 540 may cause processor 520 to perform one or more of the processes described herein.

[0072] Additionally or alternatively, hardwired circuitry systems may be used in place of or in combination with software instructions to perform one or more of the processes described herein. Therefore, the embodiments described herein are not limited to any particular combination of hardware circuitry systems and software.

[0073] Figure 5 The number and arrangement of components shown are provided as an example. In practice, device 500 may include... Figure 5 The components shown are those that are additional, fewer, different, or arranged differently compared to other components. Additionally or optionally, a set of components of device 500 (e.g., one or more components) may perform one or more functions described as being performed by another set of components of device 500.

[0074] In an embodiment, Figure 2-3 Any operation or process can be performed by Figure 4 and 5 Implement or use any of the elements shown in the diagram. Figure 4 and 5 Any of the elements shown in the diagram can be implemented. It will be understood that other embodiments are not limited to this and can be implemented in a variety of different architectures, such as bare metal architecture, any cloud-based architecture, or deployment architecture (such as Kubernetes, Docker, OpenStack, etc.).

[0075] The foregoing disclosure provides illustrations and descriptions, but is not intended to be exhaustive or to limit the implementation to the exact forms disclosed. Modifications and changes may be made based on the foregoing disclosure or through practice of the implementation methods.

[0076] Some embodiments may relate to systems, methods, and / or computer-readable media at any possible level of integration of technical detail. Furthermore, one or more of the components described above may be implemented as instructions stored on a computer-readable medium and executable by at least one processor (and / or may include at least one processor). A computer-readable medium may comprise a computer-readable non-transitory storage medium (or media) having computer-readable program instructions thereon for causing a processor to perform operations.

[0077] A computer-readable storage medium can be a tangible device capable of retaining and storing instructions for use by an instruction execution device. For example, a computer-readable storage medium can be, but is not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable media includes the following: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable optical disc read-only memory (CD-ROM), digital versatile disc (DVD), memory sticks, floppy disks, mechanical encoding devices (such as punch cards or raised structures in recesses with instructions recorded thereon), and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed as a transient signal itself, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses transmitted through fiber optic cables), or electrical signals transmitted through wires.

[0078] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a suitable computing / processing device, or downloaded via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network) to an external computer or external storage device. The network may include copper cables, optical fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the suitable computing / processing device.

[0079] Computer-readable program code / instructions used to perform operations can be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for an integrated circuit system, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​(such as Smalltalk, C++, etc.) and procedural programming languages ​​(such as the "C" programming language or similar programming languages). Computer-readable program instructions can be executed entirely on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer via any type of network (including local area network (LAN) or wide area network (WAN)) or can be connected to an external computer (e.g., via the Internet through an Internet service provider). In some embodiments, an electronic circuit system including, for example, a programmable logic circuit system, a field-programmable gate array (FPGA), or a programmable logic array (PLA) can execute computer-readable program instructions by utilizing state information from the computer-readable program instructions to personalize the electronic circuit system for performing aspects or operations.

[0080] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to generate a machine such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create parts for implementing the functions / actions specified in the flowchart and / or block diagram(s). These computer-readable program instructions may also be stored in a computer-readable storage medium that can instruct a computer, programmable data processing apparatus, and / or other device to operate in a particular manner such that the computer-readable medium having the instructions stored therein comprises an article of manufacture containing instructions for implementing the functions / actions defined in the flowchart and / or block diagram(s).

[0081] These computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operable steps to be executed on the computer, other programmable apparatus, or other device to generate a computer-implemented process so that the instructions executed on the computer, other programmable apparatus, or other device perform the functions / actions specified in the flowchart and / or block diagram boxes.

[0082] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of systems, operations, and possible implementations of computer-readable media according to various embodiments. In this respect, each block in a flowchart or block diagram may represent a portion of a microservice, module, segment, or instruction, including one or more executable instructions for implementing a specified logical function. The method, computer system, and computer-readable medium may contain additional blocks, fewer blocks, different blocks, or blocks arranged differently compared to those depicted in the drawings. In some alternative implementations, the functions annotated in the blocks may not appear in the order annotated in the drawings. For example, depending on the functions involved, in practice, two blocks shown consecutively may be executed concurrently or substantially concurrently, or the blocks may sometimes be executed in reverse order. It will also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a hardware-based dedicated system that performs the specified function or action or performs a combination of dedicated hardware and computer instructions.

[0083] It is evident that the systems and / or methods described herein can be implemented in various forms, including hardware, firmware, or a combination of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods is not a limitation on the implementation. Therefore, the operation and behavior of the system and / or method are described herein without reference to specific software code—it should be understood that software and hardware can be designed to implement the system and / or method based on the description herein.

[0084] Various aspects of the embodiments

[0085] Various other corresponding aspects and features of the embodiments of this disclosure can be defined by the following: [1] A method for policy-based data management in an Open Radio Access Network (O-RAN) Cloud (O-Cloud) infrastructure, the method comprising: storing a data policy for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policy including a definition of at least one action for a data volume from the following actions: an unmount action, a remount action, and a notification action for notifying the NF of a security threat; and performing the at least one action by the O-Cloud infrastructure based on the data policy. Item [2] is based on the method of Item [1], where the data volume is a sensitive data volume. Item [3] is based on the method of Item [1], where the O-Cloud infrastructure stores multiple data policies based on each NF. Item [4] is based on the method of any one of Items [1]-[3], wherein at least one action is performed by the O-Cloud NF runtime engine. Item [5] is a method according to any one of Items [1]-[4], wherein the definition includes at least one definition for the unloading action, the at least one definition including at least one of the following: a time-based unloading rule that defines the time at which the unloading action is performed; an interactive shell rule that defines whether the unloading action will be performed before the interactive shell request to the NF is fulfilled; an NF state rule that indicates whether the state of the NF will be considered for the execution of the unloading action; and an NF request rule that indicates whether the unloading action is requestable by the NF. Item [6] is a method according to any one of Items [1]-[5], wherein the definition includes at least one definition for a remount action, the at least one definition including at least one of the following: an allow rule that defines whether a remount action is permitted for a previously unmounted data volume; and an NF request rule that indicates whether a remount action is requestable by an NF. Item [7] is based on the method of any one of Items [1]-[6], wherein the definition includes a definition for a notification action that indicates whether a security notification for a data volume is enabled and that the security notification indicates the perceived dynamic threat level from the O-Cloud infrastructure to the NF. [8] An apparatus for policy-based data management in an Open Radio Access Network (O-RAN) Cloud (O-Cloud) infrastructure, wherein the apparatus is configured to: The O-Cloud infrastructure stores a data policy for managing network functions (NFs) deployed on the O-Cloud infrastructure. The data policy includes a definition of at least one action for a data volume, namely, an unmount action, a remount action, and a notification action for notifying the NF of a security threat. The O-Cloud infrastructure performs the at least one action based on the data policy. Item [9] is based on the apparatus of Item [8], wherein the data volume is a sensitive data volume. Item

[10] is an apparatus according to any one of Items [8]-[9], wherein the O-Cloud infrastructure stores multiple data policies based on each NF. Item

[11] The apparatus according to any one of items [8]-

[10] performs at least one action performed by the O-Cloud NF runtime engine. Item

[12] The apparatus according to any one of Items [8]-

[11] , wherein the definition includes at least one definition for the unloading action, the at least one definition including at least one of the following: a time-based unloading rule that defines the time for performing the unloading action; an interactive shell rule that defines whether the unloading action will be performed before the interactive shell request to the NF is fulfilled; an NF state rule that indicates whether the state of the NF will be considered for performing the unloading action; and an NF request rule that indicates whether the unloading action is requestable by the NF. Item

[13] The apparatus according to any one of items [8]-

[12] , wherein the definition includes at least one definition for a remount action, the at least one definition including at least one of the following: an allow rule that defines whether the remount action is permitted for a previously unmounted data volume; and an NF request rule that indicates whether the remount action is requestable by an NF. Item

[14] is an apparatus according to any one of Items [8]-

[13] , wherein the definition includes a definition for a notification action that indicates whether a security notification for a data volume is enabled and the security notification indicates the perceived dynamic threat level from the O-Cloud infrastructure to the NF.

[15] A non-transitory computer-readable recording medium having instructions recorded thereon for performing a method comprising: storing a data policy for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policy including definitions of at least one action for a data volume from the following actions: unmounting action, remounting action, and notification action for notifying the NF of a security threat; and performing the at least one action by the O-Cloud infrastructure based on the data policy. Item

[16] is a non-transitory computer-readable recording medium according to Item

[15] , wherein the data volume is a sensitive data volume. Item

[17] is a non-transitory computer-readable recording medium according to any one of Items

[15] -

[16] , wherein the O-Cloud infrastructure stores multiple data policies based on each NF. Item

[18] is a non-transitory computer-readable recording medium according to Items

[15] -

[17] , wherein at least one action is performed by the O-Cloud NF runtime engine. Item

[19] is a nontransitory computer-readable recording medium according to Items

[15] -

[18] , wherein the definition includes at least one definition for an unloading action, the at least one definition including at least one of the following: a time-based unloading rule that defines the time at which the unloading action is performed; an interactive shell rule that defines whether the unloading action will be performed before an interactive shell request to an NF is fulfilled; an NF state rule that indicates whether the state of an NF will be considered for the execution of the unloading action; and an NF request rule that indicates whether the unloading action is requestable by an NF. Item

[20] is a nontransitory computer-readable recording medium according to Items

[15] -

[19] , wherein the definition includes at least one definition for a remount action, the at least one definition including at least one of the following: an allow rule that defines whether a remount action is permitted for a previously unmounted data volume; and an NF request rule that indicates whether a remount action is requestable by an NF.

[0086] It is understandable that many modifications and variations of this disclosure are possible in accordance with the above teachings. Clearly, this disclosure may be practiced in ways other than those specifically described herein, within the scope of the appended provisions.

Claims

1. A method for policy-based data management in an Open Radio Access Network (O-RAN) cloud (O-Cloud) infrastructure, the method comprising: The O-Cloud infrastructure stores data policies for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policies including definitions for at least one of the following actions regarding data volumes: unmounting action, remounting action, and notification action for notifying the NF of security threats; as well as The O-Cloud infrastructure performs the at least one action based on the data policy.

2. The method of claim 1, wherein the data volume is a sensitive data volume.

3. The method according to claim 1, wherein the O-Cloud infrastructure stores multiple data policies based on each NF.

4. The method of claim 1, wherein the at least one action is performed by the O-Cloud NF runtime engine.

5. The method of claim 1, wherein the definition includes at least one definition for the unloading action, the at least one definition including at least one of the following: Time-based uninstallation rules define the time at which the uninstallation action is performed; An interactive shell rule that defines whether the unloading action will be performed before the interactive shell request to the NF is fulfilled; NF state rules, which indicate whether the state of the NF will be considered to perform the unloading action; as well as An NF request rule indicates whether the unload action is requestable by the NF.

6. The method of claim 1, wherein the definition includes at least one definition for the remount action, the at least one definition including at least one of the following: The permission rule defines whether the remount action is permitted for a previously unmounted data volume; and An NF request rule indicates whether the remount action is requestable by the NF.

7. The method of claim 1, wherein the definition includes a definition for the notification action, the definition indicating whether security notifications for the data volume are enabled, and the security notification indicating the perceived dynamic threat level from the O-Cloud infrastructure to the NF.

8. A system for policy-based data management in an Open Radio Access Network (O-RAN) cloud (O-Cloud) infrastructure, the system comprising: The O-Cloud infrastructure is configured as follows: The storage includes data policies for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policies including definitions for at least one of the following actions regarding data volumes: unmounting action, remounting action, and notification action for notifying the NF of security threats; as well as The at least one action is performed based on the data strategy.

9. The system of claim 8, wherein the data volume is a sensitive data volume.

10. The system of claim 8, wherein the O-Cloud infrastructure is configured to store multiple data policies based on each NF.

11. The system of claim 8, wherein the O-Cloud infrastructure includes an O-Cloud NF runtime engine configured to perform the at least one action.

12. The system of claim 8, wherein the definition includes at least one definition for the unloading action, the at least one definition including at least one of the following: Time-based uninstallation rules define the time at which the uninstallation action is performed; An interactive shell rule that defines whether the unloading action will be performed before the interactive shell request to the NF is fulfilled; NF state rules, which indicate whether the state of the NF will be considered to perform the unloading action; as well as An NF request rule indicates whether the unload action is requestable by the NF.

13. The system of claim 8, wherein the definition includes at least one definition for the remount action, the at least one definition including at least one of the following: The permission rule defines whether the remount action is permitted for a previously unmounted data volume; and An NF request rule indicates whether the remount action is requestable by the NF.

14. The system of claim 8, wherein the definition includes a definition for the notification action, the definition indicating whether security notifications for the data volume are enabled, and the security notification indicating the perceived dynamic threat level from the O-Cloud infrastructure to the NF.

15. A non-transitory computer-readable recording medium having instructions recorded thereon, the instructions being executable by at least one computer to perform a method for policy-based data management in an Open Radio Access Network (O-RAN) cloud (O-Cloud) infrastructure, the method comprising: The O-Cloud infrastructure stores data policies for managing network functions (NFs) deployed on the O-Cloud infrastructure, the data policies including definitions for at least one of the following actions regarding data volumes: unmounting action, remounting action, and notification action for notifying the NF of security threats; as well as The O-Cloud infrastructure performs the at least one action based on the data policy.

16. The non-transitory computer-readable recording medium of claim 15, wherein the data volume is a sensitive data volume.

17. The non-transitory computer-readable recording medium of claim 15, wherein the O-Cloud infrastructure stores multiple data policies based on each NF.

18. The non-transitory computer-readable recording medium of claim 15, wherein the at least one action is performed by the O-Cloud NF runtime engine.

19. The non-transitory computer-readable recording medium of claim 15, wherein the definition includes at least one definition for the unloading action, the at least one definition including at least one of the following: Time-based uninstallation rules define the time at which the uninstallation action is performed; An interactive shell rule that defines whether the unloading action will be performed before the interactive shell request to the NF is fulfilled; NF state rules, which indicate whether the state of the NF will be considered to perform the unloading action; as well as An NF request rule indicates whether the unload action is requestable by the NF.

20. The non-transitory computer-readable recording medium of claim 15, wherein the definition includes at least one definition for the remount action, the at least one definition including at least one of the following: The permission rule defines whether the remount action is permitted for a previously unmounted data volume; and An NF request rule indicates whether the remount action is requestable by the NF.