Container Secret Injection for 5G Network Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current processes for providing secrets to containers in mobile network cores face security issues, complexity, and lack of standardization, making it difficult to securely and efficiently manage dynamic runtime information, especially in 5G mobile network environments.
Innovation Solution
A method and system for managing dynamic runtime information provision in containers, which includes loading a container image with a secret subunit, determining an input source for secret values, and providing these values to the appropriate destination subunit, using metadata to standardize and automate the secret injection process, ensuring secure and standardized secret management across instances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secrets are provided to containers using current manual processes, then flexibility in secret management is maintained, but security is compromised and complexity increases
Solution Approach 1:
The patent introduces a secret management system that acts as an intermediary between secret sources and container destinations. This system automatically provisions secrets through standardized interfaces, eliminating manual handling while maintaining security. The intermediary manages the entire secret lifecycle including generation, storage, injection, and rotation without direct user intervention.
Solution Approach 2:
The secret management system enables self-service automation where the system automatically determines secret input sources, manages secret values through their lifecycle, and provisions them to appropriate container destinations without manual intervention. The system self-regulates security policies and automatically rotates secrets based on predefined criteria.
2Adaptability or versatility
If manual secret provisioning processes are used, then adaptability to different secret types is maintained, but standardization is lacking and errors increase
Solution Approach 1:
The patent creates a universal secret management system that handles multiple secret types (cryptographic keys, certificates, tokens, passwords) through a single standardized interface. The system uses metadata to automatically determine the appropriate handling for each secret type, providing both standardization and adaptability. The same provisioning mechanism works for all secret types without requiring different manual processes.
3Ease of operation
If dynamic runtime information is managed manually in containerized environments, then control over secret injection is maintained, but security risks increase and management difficulty increases
Solution Approach 1:
The system performs preliminary actions by pre-configuring secret management policies, defining input sources and destinations, and establishing security rules before secrets are actually provisioned. The metadata is prepared in advance to specify how secrets should be handled, injected, and managed throughout their lifecycle, eliminating the need for manual control during runtime while maintaining security.
4Ease of manufacture
If secrets are embedded in container images, then simplicity in deployment is achieved, but security is compromised due to potential exposure
Solution Approach 1:
The patent extracts secrets from container images and manages them separately through a dedicated secret management system. Instead of embedding secrets directly in images, the system provisions secrets dynamically at runtime based on metadata specifications. This separation maintains deployment simplicity through automation while eliminating the security risk of secret exposure in image files.
Data Source
AI summary
A method and system for managing dynamic runtime information provision for a container implementing a Session Management Function (SMF) executed by an electronic device in a 3rd generation partnership project (3GPP) 5th Generation (5G) mobile network core. The method includes starting a container image load, the container image including at least a secret sub unit and an application sub unit, the application sub unit providing the SMF, determining an input source to provide a secret value for the container, the input source identified by information in the secret sub unit in the container image, and providing the secret value to a destination sub unit of the container.


