5G Network Slice Trust Model with Cryptographic Sealing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G mobile networks face challenges in ensuring the security and integrity of data transmissions across diverse physical infrastructure, particularly in edge and far-edge datacenters where physical security measures are limited, and there is a need for a trust model that verifies slice properties and ensures only authenticated and authorized devices access trusted network slices.

Innovation Solution

Implementing a trust model using trusted computing hardware distributed across the 5G network's physical infrastructure, including radio access networks and cloud networks, which employs cryptographic sealing and unsealing of data, and layer 2 scheduling to secure data planes, along with watchdog timers for monitoring and control, to ensure that data remains bound to trusted slices and meets customer-defined policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic sealing and unsealing is implemented to bind data to trusted slices, then data security and integrity are improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing trust relationships and cryptographic bindings between data and trusted slice configurations before data transmission. The sealing process binds data to specific slice properties in advance, and the unsealing process verifies these bindings at the destination, eliminating the need for continuous complex verification operations during data flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces trusted hardware modules as intermediaries that handle the complex cryptographic sealing and unsealing operations. These trusted hardware components act as mediators between the data plane and the control plane, performing security-critical functions while shielding the rest of the system from operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If trusted hardware is distributed across edge and far-edge datacenters with limited physical security, then network coverage and service accessibility are improved, but security risks and vulnerability to compromise increase

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing security measures tailored to each deployment location's specific risk profile. Edge and far-edge datacenters with limited physical security receive enhanced cryptographic binding and trusted hardware protections, while centralized datacenters with stronger physical security can use standard configurations, optimizing both coverage and security appropriately for each location.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements beforehand cushioning by pre-configuring trusted hardware and establishing cryptographic bindings before data transmission occurs. This proactive approach creates a security buffer that protects data even in locations with limited physical security measures, compensating for the weaker physical environment through stronger logical security controls.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If slice configuration is verified against customer policy before data transmission, then service quality and customer assurance are improved, but processing time and operational complexity increase

Engineering Contradiction:
Improveservice qualityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by verifying slice configurations against customer policies in advance during slice setup and registration, rather than performing verification for each individual data transmission. This pre-verification approach establishes trust relationships beforehand, allowing rapid data transmission without repeated policy checking delays.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If layer 2 scheduling functions are instantiated in trusted hardware to secure control plane, then control security is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvecontrol securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by separating control plane functions into trusted hardware modules that handle security-critical operations. The layer 2 scheduling functions are segmented into trusted execution environments, isolating them from the rest of the system and providing focused security protection where it is most needed without complicating the entire system architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12015646B2Security for 5G network slicing
Publication Date: 2024.06.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12015646B2 patent drawing
  • US12015646B2 patent drawing
  • US12015646B2 patent drawing

AI summary

Slices of a 5G network may be configured to implement a trust model by which network customers are provided with assurances that slice properties meet agreed-upon criteria specified by customer policy so that slices can be trusted. Illustrative slice properties may pertain to service types, geographic area of operations, and attributes associated with software, firmware, and hardware used in the infrastructure of nodes in a trusted slice. Particular values of the properties describe a slice configuration that may be measured, digested, and attested to the customer to provide assurances that the configuration conforms with the policy. The 5G slice trust model may be implemented as a two-way model in which a slice provider performs checks to verify slice properties while customers ensure that only authenticated and authorized user equipment (UE) will access a trusted slice.