Container Manager Isolating Applications Across Network Slices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems lack mechanisms to clearly separate applications serving different business purposes on a device and associate them with specific network slices, leading to security concerns and inadequate isolation of resources.

Innovation Solution

Implementing a container environment with a container manager that associates each container with a unique network slice, preventing communication between applications in different containers, and using dedicated or encrypted access methods to ensure secure and isolated operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications are allowed to communicate freely across the device, then ease of operation is improved, but security is worsened due to malware spread risks

Engineering Contradiction:
Improveapplication communication freedomVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the device into multiple isolated containers, each hosting applications that require separation. This segmentation prevents malware in one container from spreading to other containers while maintaining ease of operation within each container. The container manager enforces these boundaries to ensure security without compromising operational freedom within isolated contexts.

Inventive Principle:
Principle #1Segmentation

2Productivity

If multiple applications share network resources, then productivity is improved, but reliability is worsened due to inadequate resource isolation

Engineering Contradiction:
Improveresource sharing efficiencyVSAvoidresource isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments network resource access by associating each container with specific network slices. This allows multiple applications to share network resources efficiently while maintaining reliable isolation through the container manager, which controls and monitors resource allocation to prevent interference between containers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The container manager acts as an intermediary between applications and network resources. It mediates resource allocation by controlling communication between containers and network slices, ensuring that applications can share resources productively while maintaining reliable isolation through centralized management and monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If network resources are virtualized and shared, then device complexity is reduced, but measurement precision is worsened in tracking resource usage

Engineering Contradiction:
Improvenetwork resource managementVSAvoidresource usage tracking
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The container manager implements feedback mechanisms to track resource usage across virtualized networks. It monitors and records resource consumption by each container, providing precise measurement data despite the virtualization layer. This feedback enables accurate tracking of network slice usage, container resource allocation, and application performance metrics.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3437306B1User equipment containers and network slices
Publication Date: 2023.11.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3437306B1 patent drawingFigure 1
  • EP3437306B1 patent drawingFigure 2
  • EP3437306B1 patent drawingFigure 3

AI summary

A communication device (405) comprises a container environment with a plurality of containers (FIG. 4, containers 1-x) each having one or more applications (FIG. 4, APP 1.1- x.p) and each being connectable to a network slice (FIG. 4, slices 1-x), and a container manager (FIG. 4, container manager) configured to control communication between the applications and the network slices, wherein the container manager prohibits communication between a first application in a first container and a second application in a second container.