5G Micro-Kernel Virtualization in Trusted Security Zone

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G core network is vulnerable to malicious attacks due to inadequate security in trusted execution environments, leading to disruptions in wireless network services for subscribers.

Innovation Solution

A communication device with a system-on-chip (SoC) embedding a 5G micro-kernel that executes in a trusted security zone, creating virtualized network functions to instantiate a 5G communication network, secured by a hardware root of trust, allowing for secure execution and protection against malware and viruses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the 5G core network is deployed in a traditional trusted execution environment, then the network can provide wireless data services to mobile communication devices, but the network becomes vulnerable to malicious attacks and malware

Engineering Contradiction:
Improvenetwork securityVSAvoidmalicious attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the 5G core network into virtual network function (VNF) elements that can be independently executed in isolated trusted security zones within the SoC. This segmentation allows each VNF to run in its own secure environment, preventing malware from compromising the entire network while maintaining service functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hardware root of trust as an intermediary layer between the external environment and the 5G core network VNFs. This hardware-based security anchor mediates all security-critical operations, providing a trusted execution environment that isolates the network from malicious attacks while enabling secure service delivery.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtualized network functions are embedded on a system-on-chip with hardware root of trust, then security against malware and viruses is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the 5G core network VNFs directly into the system-on-chip architecture, integrating network functionality with the device's hardware root of trust. This consolidation embeds security protections within the existing device structure rather than adding separate external security systems, thereby improving security while managing complexity through integration.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11847205B1Trusted 5G network function virtualization of virtual network function elements embedded on a system-on-chip
Publication Date: 2023.12.19 T MOBILE INNOVATIONS LLC
  • US11847205B1 patent drawing
  • US11847205B1 patent drawing
  • US11847205B1 patent drawing

AI summary

A communication device. The communication device comprises a transceiver comprising an antenna; and a system-on-chip. The system-on-chip comprises a central processing unit (CPU) and a non-transitory memory comprising a micro-kernel of a fifth generation (5G) core network that when executed by the CPU, causes the micro-kernel to begin executing instructions of the micro-kernel in a trusted security zone (TSZ) execution mode, create virtualized network functions (VNFs) of a core network in the TSZ execution mode, wherein the virtualized network functions are associated with a 5G core network, instantiate a 5G communication network using the antenna and the 5G core network in response to creating the VNFs of the core network, receive requests from subscribers of the 5G communication network, and connect the subscribers to the 5G communication network in response to receiving the requests from subscribers of the 5G communication network.