Blockchain Network Slice Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network slicing technologies face challenges in efficiently detecting unauthorized modifications and malware threats without consuming excessive resources, as traditional methods like deep packet inspection and antivirus systems are resource-intensive and not always effective.

Innovation Solution

The implementation of a distributed ledger system using blockchain technology to store immutable records of network slice integrity, where periodic state properties of network components are aggregated into slice signatures, monitored for changes, and stored in a decentralized ledger, allowing for the detection of potential threats without deep packet inspection or antivirus software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional deep packet inspection and antivirus systems are used for threat detection, then detection capability is improved, but resource consumption increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the integrity verification function from traditional resource-intensive antivirus systems and implements it through a lightweight blockchain-based mechanism. Only essential integrity data (hashes and signatures) are extracted and stored on the blockchain,而非完整的病毒扫描和深度包检测,从而大幅降低了资源消耗

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates cryptographic hash copies of network slice integrity data and stores them on the blockchain. These hash copies serve as lightweight representations that enable threat detection without requiring storage or processing of the actual network data, significantly reducing resource requirements while maintaining detection capability

Inventive Principle:
Principle #26Copying

2Reliability

If network slice integrity monitoring is implemented, then security against unauthorized modifications is improved, but system complexity increases

Engineering Contradiction:
Improveintegrity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain-based intermediary layer that mediates between network slice components and security monitoring. This intermediary automatically collects integrity data, generates cryptographic proofs, and stores them on the blockchain, simplifying the overall system architecture while enhancing integrity protection capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary integrity verification by pre-storing cryptographic hashes and digital signatures of network slice components on the blockchain before potential threats occur. This preliminary action enables rapid threat detection without requiring complex real-time analysis, reducing system complexity while maintaining high security

Inventive Principle:
Principle #10Preliminary action

3Productivity

If blockchain technology is used for integrity verification, then detection efficiency is improved, but implementation complexity increases

Engineering Contradiction:
Improvedetection efficiencyVSAvoidimplementation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the blockchain implementation into distinct functional modules: integrity data collection, hash generation, digital signature creation, and blockchain storage. Each module performs a specific function independently, improving detection efficiency through specialized processing while reducing implementation complexity through modular design that allows incremental deployment

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10917793B2Verifying network subsystem integrity with blockchain
Publication Date: 2021.02.09 T MOBILE US INC
  • US10917793B2 patent drawing
  • US10917793B2 patent drawing
  • US10917793B2 patent drawing

AI summary

In a telecommunication network, individual network slices are provided for various uses and/or for various enterprise customers. A network subsystem such as a network slice comprises multiple components, such as routers, applications, virtual network functions, etc. Each component of the subsystem generates and provides a digital signature, such as a hash, based on state properties of the component that have been designated as being invariant. The signatures from the multiple components are then combined and hashed to form a subsystem signature. A chronological sequence of subsystem signatures is saved in a distributed ledger, which may use blockchain technology to protect against after-the-fact modifications to the saved signatures. A network threat may be detected by detecting situations in which the subsystem signature of a particular subsystem changes over time. A saved blockchain, containing the sequence of signatures, can be provided as historical evidence of network integrity.