5G Network Slice Trust Verification for Secure VNF Re-Instantiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies, particularly in 5G networks, fail to provide sufficient protection against attacks, especially control flow attacks, and do not effectively monitor and manage virtual network function (VNF) instances or slices, leading to potential vulnerabilities and performance degradation.
Innovation Solution
Implementing a zero trust security framework using Adaptive Security Controller (ASC) and Distributed Ledger Technology (DLT) to verify and manage VNF instances, ensuring secure and trustworthy network slices through smart contracts and blockchains, which track and monitor device interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If layer 7 applications are deployed to improve network security, then security protection is enhanced, but system performance significantly degrades due to kernel modification
Solution Approach 1:
The patent introduces a kernel module as an intermediary component that operates between the kernel and user space. This kernel module provides security monitoring and control functions without requiring modification of layer 7 applications, thus maintaining system performance while enhancing security through a dedicated security layer that mediates between applications and the network stack
Solution Approach 2:
The patent segments security functions into a separate kernel module that can be independently loaded and managed. This segmentation allows security monitoring to be performed without affecting the performance of user-space applications, as the security functionality is isolated in its own module that operates at a lower level in the system architecture
2Reliability
If kernel modification is performed to implement security technologies, then security monitoring capability is improved, but system stability deteriorates and warranties are voided
Solution Approach 1:
The kernel module serves as an intermediary that provides security monitoring capabilities without modifying the core kernel or user-space applications. This intermediary approach maintains system stability by preserving the original system composition while adding security functionality through a separate, loadable module that can be removed without affecting system integrity
Solution Approach 2:
The kernel module is designed to be self-contained and self-managed, providing security monitoring functions independently without requiring modifications to the host system. The module can be dynamically loaded and unloaded, and maintains its own data structures and processing logic, thus serving security needs without compromising system stability or voiding warranties
3Ease of manufacture
If traditional security technologies are used, then implementation is simpler, but control flow attacks and certain attack vectors are not captured
Solution Approach 1:
The patent extends security monitoring from traditional application-layer (layer 7) to include kernel-layer monitoring capabilities. By adding this dimensional layer of monitoring, the system can detect control flow attacks and other sophisticated attack vectors that operate at lower levels, while maintaining implementation simplicity through the use of a standardized kernel module interface
4Loss of information
If monitoring tools are implemented to track attacks, then security visibility is improved, but data related to monitoring is not obfuscated providing clues to attackers
Solution Approach 1:
The patent applies different quality characteristics to different parts of the monitoring system. Sensitive monitoring data and internal system state information are obfuscated or encrypted, while necessary security visibility is maintained for authorized components. This local differentiation allows the system to provide security visibility where needed while protecting against information gathering by attackers
Data Source
AI summary
Methods and systems are provided for assigning one or more Virtual Network Function (VNF) instances, or slices, to devices, and for monitoring each change of state associated with the slices. Embodiments include applying an Advanced Security Control (ASC) protocol to verify devices for each request for access to a slice, to establish a zero trust measurement with respect to a network, such as a 5G network. In embodiments, a blockchain is associated with each slice and stored in a distributed ledger, for example to allow rapid access to network slice and device information if a slice will be re-instantiated.


