Blockchain Authentication for Telecommunication Workload Mobility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunication networks face challenges in inter-operability, roaming, and network resource sharing due to varying security levels among mobile service providers, which complicates and expenses resource sharing across different domains.
Innovation Solution
A natively integrated blockchain platform is used to authenticate and establish trust for workload mobility and network resource sharing by employing blockchain authentication functions, smart contracts, and distributed permissions ledgers, enabling secure and transparent exchanges between network entities and service providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional authentication methods are used for workload mobility across different mobile service provider domains, then security requirements become more complex and costs increase, but resource sharing and interoperability are limited
Solution Approach 1:
The patent introduces a blockchain-based authentication function as an intermediary layer between different mobile service provider domains. This mediator enables trusted workload mobility and resource sharing by providing a common authentication mechanism that all domains can participate in, without requiring complex bilateral security agreements between each pair of domains. The blockchain ledger serves as a shared trust infrastructure that simplifies cross-domain authentication.
2Reliability
If domain-specific security protocols are implemented for each mobile service provider, then security trust is maintained within domains, but interoperability and roaming between domains become difficult
Solution Approach 1:
The patent implements a universal blockchain-based authentication mechanism that can be used across all mobile service provider domains. This single authentication system serves multiple functions: it maintains security trust within individual domains, enables seamless roaming between domains, and provides a common framework for workload mobility. The distributed ledger technology allows the same authentication protocol to function reliably across diverse domain boundaries.
3Reliability
If manual authentication and trust establishment processes are used for workload migration between domains, then security can be verified, but time and operational complexity increase
Solution Approach 1:
The patent implements preliminary registration of mobile service providers and their domains in the blockchain ledger before workload mobility operations. This preliminary action establishes trust relationships in advance, so that when workload migration is needed, authentication can occur rapidly through automated blockchain verification rather than requiring time-consuming manual trust establishment processes. The smart contracts are pre-configured to automate authentication decisions.
4Device complexity
If centralized authentication systems are used for cross-domain resource sharing, then control and security management are simplified, but single points of failure and security vulnerabilities increase
Solution Approach 1:
The patent segments the authentication system into a distributed blockchain network where no single central authority controls the entire authentication process. Each mobile service provider domain maintains its own security policies and authentication capabilities, while the blockchain ledger provides a distributed consensus mechanism for cross-domain trust verification. This segmentation eliminates single points of failure while maintaining simplified authentication workflows through automated smart contract execution.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
A network slice manager receives a workload mobility request to add network resources to a domain in the communication network, and authenticates a virtual network function (VNF) with a blockchain authentication function (BAF) over a blockchain network interface based on the workload mobility request. The network slice manager further receives an indication of a successful authentication from the BAF, and instantiates the VNF in the domain of the communication network based on the indication of the successful authentication. Notably, these authentication processes may be readily adapted to instantiate new network resources or migrate existing network resources between domains.