5G private network security management and control all-in-one machine

The integration of a Trusted Platform Control Module in 5G networks addresses security vulnerabilities by providing automated verification and monitoring, enhancing network security and simplifying deployment.

CN223110034UActive Publication Date: 2025-07-15ISOFT INFRASTRUCTURE SOFTWARE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202422263068.0
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2024-09-14
Publication Date
2025-07-15
Estimated Expiration
2034-09-14

AI Technical Summary

Technical Problem

Traditional 5G private network security solutions are difficult to meet the needs of customers with high security attributes. The hardware platform is susceptible to malware and unauthorized access during startup. The security of system images and key components is difficult to guarantee, and there is a risk of being tampered with or implanted with malicious code.

Method used

It adopts a 5G private network security management and control machine, which integrates processor modules, input and output modules, programmable logic modules, business operation and maintenance modules, business operation and maintenance storage modules and trusted platform control modules. Through trusted computing technology, it realizes automated hardware security verification, system mirroring loading, remote management function configuration and real-time monitoring of trusted computing strategies.

Benefits of technology

It significantly improves the security and reliability of the system, simplifies the deployment process, improves the stability and ease of use of the system, realizes rapid deployment and efficient network protection, and meets the needs of customers with high security attributes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN223110034U_ABST
    Figure CN223110034U_ABST
Patent Text Reader

Abstract

The utility model provides a 5G private network security management and control all-in-one machine, which belongs to the technical field of network communication and security and comprises a processor module, an input and output module, a programmable logic module, a service operation and maintenance module, a service operation and maintenance storage module and a trusted platform control module. The processor module is electrically connected with the input and output module through a first data bus, and the service operation and maintenance module is electrically connected with the service operation and maintenance storage module through a second data bus; the trusted platform control module is electrically connected with the processor module, the programmable logic module, the first data bus and the second data bus. The beneficial effects are that the trusted platform control module is introduced, the security and reliability of the system are enhanced based on the trusted computing technology, the deployment efficiency is improved through the pre-integrated software and hardware deployment all-in-one machine, the security level of the 5G private network is improved, and the private network management and control platform with software and hardware integration, rapid deployment and ready-to-use after box opening is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The utility model relates to the technical field of network communication and security, and particularly relates to a 5G private network security control integrated machine based on trusted computing. Background Art

[0002] With the rapid development and wide application of 5G technology, its characteristics of high speed, low latency and large connection have brought unprecedented changes and opportunities to all walks of life, making the deployment of 5G private networks in industrial customers increasing day by day.

[0003] However, while enjoying the convenience and efficiency improvement brought by 5G technology, network security problems have become increasingly prominent, and traditional network security means are difficult to meet the needs of customers with high security attributes. Specifically, the hardware platform lacks an effective security verification mechanism during the startup process, is vulnerable to malware and unauthorized access threats, and seriously threatens the security and stability of the system; moreover, the security of system images and key components is difficult to guarantee, and there is a risk of being tampered with, replaced or implanted with malicious code, further exacerbating security risks.

[0004] Trusted computing, as a computer system security technology that combines cryptographic operations and protection, can fundamentally improve the security of the system. However, there is currently a lack of a solution that effectively combines trusted computing technology with a 5G private network security control integrated machine in the market. Summary of the Utility Model

[0005] In order to solve the above technical problems, the utility model provides a 5G private network security control integrated machine.

[0006] The technical problems solved by the utility model can be realized by adopting the following technical solutions:

[0007] A 5G private network security control integrated machine includes a processor module, an input / output module, a programmable logic module, a service operation and maintenance module, a service operation and maintenance storage module, and a trusted platform control module;

[0008] The processor module is electrically connected to the input / output module through a first data bus, and the service operation and maintenance module is electrically connected to the service operation and maintenance storage module through a second data bus;

[0009] The trusted platform control module is electrically connected to the processor module, the programmable logic module, the first data bus, and the second data bus respectively.

[0010] Preferably, the trusted platform control module is electrically connected to the processor module through a high-speed data bus.

[0011] Preferably, the trusted platform control module is electrically connected to the programmable logic module through a power control bus.

[0012] Preferably, the trusted platform control module is electrically connected to the first data bus through a first main control bus.

[0013] Preferably, the trusted platform control module is electrically connected to the second data bus through a second main control bus.

[0014] Preferably, it further includes: a chassis, and the processor module, the input / output module, the programmable logic module, the service operation and maintenance module, the service operation and maintenance storage module, and the trusted platform control module are all integrated in the chassis.

[0015] Preferably, an optical fiber network card is further integrated on the chassis, and the optical fiber network card is electrically connected to the processor module.

[0016] Preferably, a disk array card is further integrated on the chassis, and the disk array card is electrically connected to the processor module.

[0017] Preferably, the processor module includes a central processing unit;

[0018] The input / output module includes a basic input / output system;

[0019] The programmable logic module includes a complex programmable logic device;

[0020] The service operation and maintenance module includes a baseboard management controller;

[0021] The service operation and maintenance storage module includes a flash memory.

[0022] Preferably, the 5G private network security control all-in-one machine is communicatively connected to a WEB browser running on a WEB server through the HTTP protocol, and the WEB browser provides a WEB management interface for remote access and configuration management.

[0023] The advantages or beneficial effects of the technical solution of the present invention are as follows:

[0024] By introducing a trusted platform control module, the present invention enhances the security and reliability of the system based on trusted computing technology, and improves the deployment efficiency through pre-integrated software and hardware to deploy the all-in-one machine, aiming to improve the security level of the 5G private network and realize a private network control platform with software and hardware integration, fast deployment, and out-of-the-box use. Description of the Drawings

[0025] Figure 1 It is the architecture diagram of the 5G private network integrated security control platform in the preferred embodiment of the present invention;

[0026] Figure 2 In a preferred embodiment of the present invention, it is a structural block diagram of a 5G private network security control integrated machine based on trusted computing;

[0027] Figure 3 In a preferred embodiment of the present invention, it is a schematic flow diagram of the trusted computing verification process;

[0028] Figure 4 In a preferred embodiment of the present invention, it is a schematic diagram of the dynamic measurement process of trusted computing;

[0029] Figure 5 In a preferred embodiment of the present invention, it is a schematic flow diagram of the dynamic measurement process of trusted computing. Detailed implementation manners

[0030] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0031] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0032] Next, the present invention will be further described in conjunction with the accompanying drawings and specific embodiments, but it is not a limitation of the present invention.

[0033] With the large-scale application of 5G technology in industrial customers, network security issues have become increasingly prominent. Existing network security solutions often require a complex deployment process and have limitations in terms of performance and security. To address these challenges, a security control platform that can be quickly deployed, operate efficiently, and have a strong security protection ability is needed. The present invention utilizes trusted computing technology to provide a higher level of security guarantee through deep integration of hardware and software. A deployment and initialization method for a 5G private network control platform integrated machine integrating a trusted platform control module 600 (TPCM) is provided, which significantly enhances the security and integrity of the system, simplifies the deployment process, improves the reliability and stability of the system, and promotes the innovation and development of network security technology in the field of 5G private network control.

[0034] Please refer to Figure 1 , Figure 1The architecture diagram of the 5G private network integrated security control platform is shown. The 5G private network integrated security control platform can be applied to scenarios such as education, finance, energy, transportation, and government affairs. The platform includes a service layer, an application layer, and an infrastructure layer; among them,

[0035] The service layer can be compatible with various terminal devices such as PADs, mobile phones, and industrial terminals;

[0036] The application layer includes a 5G private network security management system, which can enter the management interface through a WEB browser to achieve remote access and configuration management;

[0037] The infrastructure layer includes a customized hardware platform and an operating system; the infrastructure layer includes the 5G private network security control all-in-one machine provided by the embodiment of the present utility model; the operating system is an operating system developed based on trusted computing technology, which realizes functions such as trusted boot, dynamic monitoring, access permission control, and integrity verification. The operating system also provides a standard OpenAPI capability open interface to support the flexible deployment and invocation of third-party applications.

[0038] Please refer to Figure 2 , in a preferred embodiment of the present utility model, in view of the above problems existing in the prior art, a 5G private network security control all-in-one machine based on trusted computing is provided, which includes a processor module 100, an input / output module 200, a programmable logic module 300, a service operation and maintenance module 400, a service operation and maintenance storage module 500, and a trusted platform control (Trusted Platform Control Module, TPCM) module 600;

[0039] The processor module 100 is electrically connected to the input / output module 200 through a first data bus 701, and the service operation and maintenance module 400 is electrically connected to the service operation and maintenance storage module 500 through a second data bus 702;

[0040] The trusted platform control module 600 is electrically connected to the processor module 100, the programmable logic module 300, the first data bus 701, and the second data bus 702 respectively.

[0041] Specifically, aiming at the problems existing in the traditional 5G private network control platform in terms of security, system integrity protection, deployment efficiency, system stability, and network security technology, in this embodiment, by integrating the trusted platform control module 600 inside the all-in-one machine, the trusted platform control module 600 serves as the only trust source point of the entire all-in-one machine system and undertakes the core security protection management responsibility. The TPCM trusted computing technology aims to achieve comprehensive security monitoring and management of the platform through an architecture independent of the server computing unit, significantly improving the security level of the 5G private network and meeting the needs of customers with high security attributes.

[0042] As a preferred embodiment, the trusted platform control module 600 is electrically connected to the processor module 100 through a high-speed data bus 703.

[0043] As a preferred embodiment, the trusted platform control module 600 is electrically connected to the programmable logic module 300 through a power control bus 704.

[0044] As a preferred embodiment, the trusted platform control module 600 is electrically connected to the first data bus 701 through a first main control bus 705.

[0045] As a preferred embodiment, the trusted platform control module 600 is electrically connected to the second data bus 702 through a second main control bus 706.

[0046] As a preferred embodiment, it further includes: a chassis (not shown in the figure), and the processor module 100, the input / output module 200, the programmable logic module 300, the service operation and maintenance module 400, the service operation and maintenance storage module 500, and the trusted platform control module 600 are all integrated in the chassis.

[0047] Specifically, in this embodiment, by integrating key hardware such as the high-performance processor module 100, the input / output module 200, the programmable logic module 300, the service operation and maintenance module 400, the service operation and maintenance storage module 500, and the trusted platform control module 600 inside the all-in-one machine, the security of the underlying basic hardware is ensured.

[0048] As a preferred embodiment, a fiber optic network card (not shown in the figure) is also integrated on the chassis, and the fiber optic network card is electrically connected to the processor module 100.

[0049] As a preferred embodiment, a disk array (RAID) card (not shown in the figure) is also integrated on the chassis, and the disk array card is electrically connected to the processor module 100.

[0050] Specifically, in this embodiment, with the minimalist design concept, functions such as the fiber optic network card and the RAID card are integrated in a 2U-high chassis to achieve full integration.

[0051] The present utility model provides functions of out-of-the-box and one-key deployment. The user only needs to connect the power supply and the network cable, and the all-in-one machine can automatically power on and complete the initialization configuration, reducing the deployment cost, improving the deployment efficiency, and enhancing the user experience.

[0052] As a preferred embodiment, the processor module 100 includes a central processing unit (CPU);

[0053] The input / output module 200 includes a Basic Input / Output System (BIOS);

[0054] The programmable logic module 300 includes a Complex Programmable Logic Device (CPLD);

[0055] The service operation and maintenance module 400 includes a Baseboard Management Controller (BMC);

[0056] The service operation and maintenance storage module 500 includes a Flash Memory.

[0057] Specifically, install the customized hardware platform (i.e., the 5G private network security control all-in-one machine) to the specified location and complete the physical connection. After the all-in-one machine is powered on, the first step involves powering on the TPCM, CPLD, and Flash memory. At this stage, the TPCM is responsible for dynamically measuring and checking the BIOS and BMC codes to verify whether there are any abnormalities or unauthorized tampering. If the firmware is detected to be tampered with, the TPCM will initiate preventive measures according to the preset security policy, including preventing the system from further powering on or issuing a warning and allowing entry into a non-trusted operating environment in the case of a lenient security policy. If the code environment is normal, the TPCM will trigger the power-on of the second step.

[0058] Second step: The BMC starts to execute and conducts authentication interaction with the TPCM to ensure the trustworthiness of the BMC system environment. After confirmation, the TPCM will authorize the power-on of the third step; if there are security risks, it will prevent power-on or guide the server into a non-trusted state.

[0059] Third step: The CPU of the server is officially started and executes instructions. The TPCM conducts environmental identification and confirmation again to ensure the security of the main computing system. After the environment is confirmed to be trustworthy, the server will conduct a self-check and continue the startup process; if a security problem is detected, the server will enter a non-trusted environment or directly shut down the power to prevent potential security threats.

[0060] During the initial power-on process, the CPLD detects the presence of the TPCM through the presence signal of the TPCM. Once the TPCM is confirmed to be valid, the CPLD will cut off the main control buses (including the first main control bus 705 and the second main control bus 706), allowing the TPCM to control the connection between the BMC Flash Memory and the BIOS, while keeping the power supplies of the second and third steps in the off state and waiting for further instructions from the TPCM. After the TPCM is powered on, it performs self-checks to ensure its own security, and then, according to the security policy preset by the user, it conducts segmented inspections on the BMC and BIOS codes. Any unauthorized intrusion or data change will trigger the alarm mechanism of the TPCM and may take measures such as blocking the main power supply or closing the communication port. After confirming the credibility of the codes, the TPCM instructs the CPLD to turn on the power supplies of the second and third steps in sequence and continue to perform subsequent trusted environment checks.

[0061] The TPCM module is used to encrypt the data stream processed by the CPU and simultaneously monitor the underlying system status to implement basic functions such as identity authentication, security measurement, and cryptographic services.

[0062] Furthermore, based on the verification steps of trusted computing, it provides a solid guarantee for the secure loading of the system image and the operation of the 5G private network security management software. The trusted computing verification process includes the following four parts:

[0063] Verify the credibility of the hardware and firmware with the trusted root;

[0064] Verify the credibility of the operating system boot with the verification mechanism of the firmware;

[0065] Verify the credibility of the system with the operating system boot program;

[0066] Verify the credibility of the security management software with a customized verification mechanism.

[0067] Please refer to Figure 3 , the trusted computing verification process performs the following steps:

[0068] a. Execute the hardware POST, and the TPCM participates in detecting the integrity of the hardware OpRom and the BIOS Boot Block to ensure the stable operation of the hardware components without faults.

[0069] b. UEFI boot phase and TPCM verification:

[0070] After the POST is completed, the boot sector is detected through UEFI, and the TPCM verifies the security and integrity of the boot program. The boot program starts to execute and loads the kernel.

[0071] c. Kernel loading and TPCM trusted verification:

[0072] The bootloader loads the kernel, and the TPCM performs a trust verification again to ensure the security and integrity of the kernel.

[0073] d, System image file startup and automatic loading:

[0074] After the kernel is loaded, the system automatically starts and loads through the pre-configured image file. The TPCM monitors the loading process of the image file to ensure the security of the 5G security control software and basic configurations.

[0075] e, System startup and continuous TPCM verification:

[0076] During the system startup process, the TPCM records and verifies the system startup status to ensure the integrity and authenticity of the system environment.

[0077] f, Application startup and TPCM monitoring:

[0078] After the system startup is completed, the 5G security control application is loaded and started. The TPCM continues to monitor the startup process of the application to ensure the security of the application.

[0079] f, Execution and configuration of automation scripts:

[0080] Start the automation deployment script to complete the detailed configuration of the system, including network settings, user authentication, security policy loading, etc. The TPCM ensures that every step in the configuration process meets the security requirements.

[0081] h, Configuration of remote management functions:

[0082] Configure the remote management interface and implement security measures such as access control lists and encrypted transmission protocols to ensure the security of the remote management channel.

[0083] i, System testing and verification:

[0084] Conduct comprehensive functional and performance tests on the deployed system, perform security vulnerability scans and penetration tests, and verify the logs recorded by the TPCM and the security protection capabilities of the system.

[0085] j, Configuration of trusted computing policies:

[0086] Configure trusted computing policies, implement regular security audits, check the logs of the TPCM, and ensure the continuous integrity and security of the system.

[0087] Through the implementation of the present utility model, the security and reliability of the 5G private network control platform all-in-one machine during deployment and operation have been significantly improved. It not only solves the deficiencies of traditional network security solutions in terms of deployment and performance but also realizes efficient, intelligent, and secure network protection through the close integration and collaborative work of software and hardware. Meanwhile, the introduction of rapid deployment has greatly enhanced the usability and deployment efficiency of the system, providing strong support for security protection in the modern network environment.

[0088] Furthermore, through the trusted measurement mechanism, it is ensured that the critical files of the system are subject to trusted verification before being loaded into the kernel, thereby improving the overall security level of the system. The hardware, firmware, and software of the TPCM provide a running environment for the Trusted Software Base (TSB), and the set trusted functional components support the TSB to implement functions such as measurement, control, support, and decision-making according to the requirements interpreted by the policy library. As Figure 4 shown, when the system process calls the critical kernel data in the kernel layer, the TPCM performs dynamic measurement based on the trusted software base.

[0089] As Figure 5 shown, the dynamic measurement process of the all-in-one machine application is as follows:

[0090] A1. The application verifies whether the user identity belongs to the whitelist users:

[0091] If so, it is confirmed as a trusted user, and further behavior detection is performed, and at the same time, it enters A2 and A3;

[0092] If not, its access permission is immediately blocked;

[0093] A2. Judge whether the behavior is compliant:

[0094] If so, the program is executed normally;

[0095] If not, its access permission is immediately blocked;

[0096] A3. Perform dynamic measurement and judge the operation mode:

[0097] If it is compliant, record its running status for subsequent auditing or analysis;

[0098] If it is abnormal, its access permission is immediately blocked to ensure the security and integrity of the critical data in the kernel layer are not violated and prevent potential security risks.

[0099] As a preferred implementation manner, among them, the 5G private network security control all-in-one machine is communicatively connected to a WEB browser running on a WEB server through the HTTP protocol, and the WEB browser provides a WEB management interface for remote access and configuration management.

[0100] Specifically, by equipping it with an intuitive WEB management interface, users can remotely access and perform configuration management through a browser without the need for professional knowledge, thus simplifying the operating process and lowering the threshold for use.

[0101] The advantages or beneficial effects of adopting the above technical solution are: the utility model introduces a trusted platform control module 600, enhances the security and reliability of the system based on trusted computing technology, improves deployment efficiency through a pre-integrated software and hardware deployment all-in-one machine, aims to improve the security level of the 5G private network, and realizes a private network management and control platform that integrates software and hardware, is quickly deployed, and is ready to use out of the box.

[0102] It should be noted that the utility model aims to solve the problems of the traditional 5G private network control platform in terms of security, system integrity protection, deployment efficiency, system stability and network security technology, so as to meet the actual application needs. The utility model belongs to industrial innovation through the combination of the trusted platform control module 600 and the 5G private network control platform integrated machine; the utility model does not involve any innovation in software. Although trusted computing technology is inseparable from software codes, these software codes belong to the prior art. Those skilled in the art only need to cut or transplant the existing codes to the utility model. Of course, they can also be written in accordance with the product technical documents. Therefore, what the utility model wants to protect is the hardware connection relationship, and does not involve innovation in software. The embodiments and preferred embodiments involved in the above are all understood in this way.

[0103] The above are only preferred embodiments of the present invention, and are not intended to limit the implementation methods and protection scope of the present invention. Those skilled in the art should be aware that all solutions obtained by equivalent substitutions and obvious changes made using the contents of this specification and illustrations should be included in the protection scope of the present invention.

Claims

1. A 5G private network security control all-in-one machine, characterized in that, It includes a processor module, an input / output module, a programmable logic module, a service operation and maintenance module, a service operation and maintenance storage module, and a trusted platform control module; The processor module is electrically connected to the input / output module through a first data bus, and the service operation and maintenance module is electrically connected to the service operation and maintenance storage module through a second data bus; The trusted platform control module is electrically connected to the processor module, the programmable logic module, the first data bus, and the second data bus respectively.

2. The 5G private network security control integrated machine according to claim 1, characterized in that, The trusted platform control module is electrically connected to the processor module through a high-speed data bus.

3. The 5G private network security control integrated machine according to claim 1, characterized in that, The trusted platform control module is electrically connected to the programmable logic module through a power control bus.

4. The 5G private network security control integrated machine according to claim 1, characterized in that The trusted platform control module is electrically connected to the first data bus through a first main control bus.

5. The 5G private network security control integrated machine according to claim 1, characterized in that, The trusted platform control module is electrically connected to the second data bus through a second main control bus.

6. The 5G private network security control all-in-one machine according to claim 1, characterized in that It further includes: A chassis, and the processor module, the input / output module, the programmable logic module, the service operation and maintenance module, the service operation and maintenance storage module, and the trusted platform control module are all integrated in the chassis.

7. The 5G private network security control integrated machine according to claim 6, characterized in that, An optical fiber network card is also integrated on the chassis, and the optical fiber network card is electrically connected to the processor module.

8. The 5G private network security control all-in-one machine according to claim 6, characterized in that, A disk array card is also integrated on the chassis, and the disk array card is electrically connected to the processor module.

9. The 5G private network security control integrated machine according to claim 1, wherein The processor module includes a central processing unit; The input / output module includes a basic input / output system; The programmable logic module includes a complex programmable logic device; The service operation and maintenance module includes a baseboard management controller; The service operation and maintenance storage module includes a flash memory.

10. The 5G private network security control integrated machine according to claim 1, wherein The 5G private network security control all-in-one machine communicates with a WEB browser running on a WEB server through the HTTP protocol, and the WEB browser provides a WEB management interface for remote access and configuration management.