5G Network Slice Trust Verification for Secure VNF Re-Instantiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies, particularly in 5G networks, fail to provide sufficient protection against attacks, especially control flow attacks, and do not effectively monitor and manage virtual network function (VNF) instances or slices, leading to potential vulnerabilities and performance degradation.

Innovation Solution

Implementing a zero trust security framework using Adaptive Security Controller (ASC) and Distributed Ledger Technology (DLT) to verify and manage VNF instances, ensuring secure and trustworthy network slices through smart contracts and blockchains, which track and monitor device interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If layer 7 applications are deployed to improve network security, then security protection is enhanced, but system performance significantly degrades due to kernel modification

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a kernel module as an intermediary component that operates between the kernel and user space. This kernel module provides security monitoring and control functions without requiring modification of layer 7 applications, thus maintaining system performance while enhancing security through a dedicated security layer that mediates between applications and the network stack

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security functions into a separate kernel module that can be independently loaded and managed. This segmentation allows security monitoring to be performed without affecting the performance of user-space applications, as the security functionality is isolated in its own module that operates at a lower level in the system architecture

Inventive Principle:
Principle #1Segmentation

2Reliability

If kernel modification is performed to implement security technologies, then security monitoring capability is improved, but system stability deteriorates and warranties are voided

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidsystem stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The kernel module serves as an intermediary that provides security monitoring capabilities without modifying the core kernel or user-space applications. This intermediary approach maintains system stability by preserving the original system composition while adding security functionality through a separate, loadable module that can be removed without affecting system integrity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The kernel module is designed to be self-contained and self-managed, providing security monitoring functions independently without requiring modifications to the host system. The module can be dynamically loaded and unloaded, and maintains its own data structures and processing logic, thus serving security needs without compromising system stability or voiding warranties

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If traditional security technologies are used, then implementation is simpler, but control flow attacks and certain attack vectors are not captured

Engineering Contradiction:
Improveimplementation simplicityVSAvoidattack detection capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent extends security monitoring from traditional application-layer (layer 7) to include kernel-layer monitoring capabilities. By adding this dimensional layer of monitoring, the system can detect control flow attacks and other sophisticated attack vectors that operate at lower levels, while maintaining implementation simplicity through the use of a standardized kernel module interface

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Loss of information

If monitoring tools are implemented to track attacks, then security visibility is improved, but data related to monitoring is not obfuscated providing clues to attackers

Engineering Contradiction:
Improvesecurity visibilityVSAvoidattacker information gathering
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different quality characteristics to different parts of the monitoring system. Sensitive monitoring data and internal system state information are obfuscated or encrypted, while necessary security visibility is maintained for authorized components. This local differentiation allows the system to provide security visibility where needed while protecting against information gathering by attackers

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12477328B1Systems and methods for implementing a zero trust model in connection with 5G networks
Publication Date: 2025.11.18 T MOBILE INNOVATIONS LLC
  • US12477328B1 patent drawing
  • US12477328B1 patent drawing
  • US12477328B1 patent drawing

AI summary

Methods and systems are provided for assigning one or more Virtual Network Function (VNF) instances, or slices, to devices, and for monitoring each change of state associated with the slices. Embodiments include applying an Advanced Security Control (ASC) protocol to verify devices for each request for access to a slice, to establish a zero trust measurement with respect to a network, such as a 5G network. In embodiments, a blockchain is associated with each slice and stored in a distributed ledger, for example to allow rapid access to network slice and device information if a slice will be re-instantiated.