5G Network Slice Timing Obfuscation Against Side-Channel Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G network slices are vulnerable to side-channel attacks that allow attackers to gain access to sensitive data across slice boundaries due to logical rather than physical isolation, compromising security in shared resource environments.

Innovation Solution

Implementing time-based constraints such as fixed data packet lengths and intervals, along with temporal isolation and hardening virtualized network functions to operate in constant time, obscures data-driven time variations and prevents timing leakage, thereby enhancing resistance to side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network slicing is implemented to support diverse 5G services, then service diversity and customization are improved, but system complexity and vulnerability to side-channel attacks increase

Engineering Contradiction:
Improveservice diversityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the network slicing management into separate security domains. A security domain identifier is embedded in each network slice configuration, and security policies are enforced at each domain boundary. This segments the complex multi-tenant system into isolated security zones, reducing overall system complexity while maintaining service diversity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security domain as an intermediary layer between different network slices. This intermediary enforces isolation policies and prevents side-channel attacks by mediating resource access between slices. The security domain acts as a buffer that manages the complexity of inter-slice interactions while preserving service customization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If resource virtualization is used to improve network efficiency, then resource utilization is improved, but side-channel attack surfaces increase

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidside-channel attack surface
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by preemptively embedding security domain identifiers in network slice configurations before resources are allocated. Security policies are pre-configured to prevent side-channel attacks at the virtualization layer. This preliminary security enforcement neutralizes potential attack vectors before they can exploit virtualized resources.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent applies local quality by implementing differentiated security policies for different security domains within the virtualized network. Each domain receives customized security enforcement based on its specific requirements. This localized security approach protects against side-channel attacks while maintaining high resource utilization through selective isolation rather than blanket restrictions.

Inventive Principle:
Principle #3Local quality

3Loss of energy

If multiple tenants share network resources to reduce costs, then cost efficiency is improved, but security isolation requirements increase

Engineering Contradiction:
Improvecost efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The patent applies universality by creating a multi-functional security domain framework that serves multiple tenants with different security requirements. The same security infrastructure enforces isolation across diverse network slices while allowing resource sharing. This universal approach maintains security isolation reliability without requiring separate physical infrastructure for each tenant, thus preserving cost efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If security measures are strengthened to prevent side-channel attacks, then security reliability is improved, but system performance and flexibility deteriorate

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making security domain configurations adaptable and changeable. Security policies can be dynamically adjusted based on service requirements and threat levels. The security domain identifier and associated policies can be modified without reconfiguring the entire network, maintaining system flexibility while ensuring security reliability through enforceable isolation boundaries.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4402590B1Resistance to side-channel attacks on 5g network slices
Publication Date: 2026.04.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4402590B1 patent drawingFigure 1
  • EP4402590B1 patent drawingFigure 2
  • EP4402590B1 patent drawingFigure 3

AI summary

Resistance to vulnerabilities from timing-based side-channel attacks on 5G network slices that share underlying physical infrastructure and resources may be enhanced by selectively imposing time-based constraints on service provisioning and data handling to obscure data-driven time variations that occur during workload execution in a slice that can leak secret information. By preventing timing leakage from the 5G network slices, an attacker cannot observe execution latencies to thereby infer the constituency of workload characteristics. In addition, the attacker cannot create contention for shared resources on its own slice to observe an extent to which the shared resources are utilized by a targeted slice.