Blockchain Orchestrator for 5G VNF Container Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems lack secure methods for creating and managing virtual network functions (VNFs) in 5G networks, particularly for user plane and control plane elements, which are vulnerable to malicious attacks and unauthorized requests.

Innovation Solution

A blockchain-based front-end orchestrator is implemented to create cryptographic blockchain data that is appended to containers during VNF creation or modification, providing a permanent ledger for tracking activity and enhancing network security by authenticating requests and detecting unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtual machine-based VNF implementation is used, then system compatibility is maintained, but security against malicious attacks is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces blockchain technology as an intermediary layer between the container orchestrator and VNF containers. The blockchain front-end orchestrator validates container images and requests by checking cryptographic proofs on the blockchain ledger, providing secure verification without requiring changes to the underlying containerization infrastructure. This mediator approach enhances security while maintaining system compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional trust-based mechanical verification mechanisms with cryptographic verification based on blockchain technology. Instead of relying on centralized authority or manual security checks, the system uses cryptographic proofs (merkle trees, digital signatures) to automatically verify container image integrity and request authenticity, substituting mechanical trust with mathematical certainty.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If container orchestrator is implemented for VNF management, then deployment flexibility is improved, but vulnerability to unauthorized requests increases

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary validation of container images by creating cryptographic merkle trees and storing them on the blockchain before deployment. The front-end orchestrator pre-validates container images and requests by checking their cryptographic proofs against the blockchain ledger, preventing unauthorized or malicious containers from being deployed in the first place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where the blockchain front-end orchestrator constantly validates container images and requests against the blockchain ledger. The validation process provides real-time feedback on whether containers are authorized, and the system can reject unauthorized requests immediately, creating a closed-loop security mechanism that adapts to new threats.

Inventive Principle:
Principle #23Feedback

3Reliability

If blockchain-based validation is implemented, then security and authenticity are enhanced, but processing time increases

Engineering Contradiction:
ImproveauthenticityVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary cryptographic validation of container images by creating merkle trees and storing proofs on the blockchain before deployment. This advance preparation allows the front-end orchestrator to quickly verify container authenticity during runtime by simply checking cryptographic proofs against pre-stored blockchain data, rather than performing complex validation operations in real-time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates cryptographic copies (merkle trees, digital signatures, hash values) of container image data and stores them on the blockchain. During validation, the orchestrator compares cryptographic copies rather than analyzing the entire container image content, dramatically reducing validation time while maintaining security. The cryptographic copies serve as lightweight proxies for full verification.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11172358B2Blockchain-based front-end orchestrator for user plane network functions of a 5G network
Publication Date: 2021.11.09 AT&T MOBILITY II LLC
  • US11172358B2 patent drawing
  • US11172358B2 patent drawing
  • US11172358B2 patent drawing

AI summary

Containers and container orchestration can be utilized for the creation of an environment that supports virtual network functions (VNFs) representing user plane and/or control plane gateways of 5G networks. Security and/or performance of the 5G network is improved by utilizing blockchain ledgers representing activity associated with the containers. In one aspect, cryptographic blockchain data is appended to a container when the VNF is created and/or modified. The cryptographic blockchain data can create a permanent ledger of activity on the container, which can be utilized to detect malicious attacks and/or unauthorized requests, and/or track activity associated with containers that are utilized to support high performance users and/or services. Further, the cryptographic blockchain data can be utilized for various applications, such as, but not limited to, security, accounting, network performance, governance and risk compliance, etc.