Distributed Ledger for Secure RRM Application Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment of radio resource management (RRM) applications in 5G Open Radio Access Networks (O-RAN) faces challenges due to potential interoperability issues and security threats from third-party applications, as well as the lack of a trusted root of trust for validating the origin and integrity of these applications.

Innovation Solution

The use of distributed ledger technology, specifically a permissioned blockchain, to securely register and deploy RRM applications by cryptographically signing records that define deployment methods and contain application data, ensuring a non-repudiable root of trust and secure communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party applications are allowed in Open RAN for increased functionality and vendor interoperability, then adaptability and versatility improve, but security threats and reliability deteriorate due to potential malicious applications and lack of trusted root of trust

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A blockchain-based intermediary system is introduced between application vendors and RAN controllers. The blockchain ledger acts as a trusted mediator that stores cryptographically signed application records, enabling verification of application origin and integrity without requiring direct trust between vendors and network operators. This intermediary mechanism resolves the security-risk contradiction by providing a neutral, decentralized trust anchor.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Applications are pre-registered and cryptographically signed in the blockchain ledger before deployment to RAN controllers. This preliminary action of registering application metadata, vendor identifiers, and digital signatures in advance enables automatic verification during deployment, preventing malicious applications from being installed without proper authentication. The advance preparation of trusted application records resolves the contradiction by establishing security checks before functionality is activated.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If traditional centralized application deployment methods are used, then device complexity is reduced, but adaptability and ease of operation deteriorate due to lack of flexibility in deploying applications from multiple vendors

Engineering Contradiction:
Improvedeployment systemVSAvoidapplication deployment flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The blockchain ledger serves as a universal platform that handles multiple functions: application registration, vendor authentication, deployment method specification, and integrity verification. This single multi-functional system replaces complex centralized deployment architectures while enabling flexible multi-vendor application deployment. The universal blockchain infrastructure resolves the contradiction by consolidating complexity into a standardized protocol that supports diverse application scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

RAN controllers automatically retrieve application records from the blockchain ledger and execute deployment based on instructions stored in the ledger. The system enables self-service deployment where controllers autonomously verify application integrity using cryptographic signatures and apply applications without requiring complex centralized coordination. This self-service mechanism reduces device complexity while improving deployment adaptability through automated, standardized processes.

Inventive Principle:
Principle #25Self-service

3Reliability

If cryptographic signing of application records is implemented, then reliability and security improve through non-repudiable root of trust, but device complexity and difficulty of operation increase due to cryptographic operations

Engineering Contradiction:
Improveapplication integrityVSAvoidcryptographic processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of implementing complex cryptographic verification in each RAN controller, the system stores pre-computed cryptographic signatures and application metadata as copies in the blockchain ledger. Controllers simply retrieve and verify these copied records using standardized cryptographic libraries, rather than performing complex cryptographic operations or managing key infrastructure. This copying approach maintains high reliability through cryptographic verification while reducing operational complexity by using standardized, well-tested cryptographic primitives.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If distributed ledger technology is deployed for application management, then adaptability and security improve, but device complexity and use of energy increase due to blockchain infrastructure requirements

Engineering Contradiction:
Improvemulti-vendor application supportVSAvoidblockchain processing energy
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The energy-intensive blockchain consensus and validation operations are extracted from individual RAN controllers and centralized in dedicated blockchain network nodes. RAN controllers only perform lightweight operations of retrieving and verifying pre-validated application records from the blockchain, without participating in energy-consuming consensus processes. This extraction separates the heavy computational workload from edge devices, enabling multi-vendor application support with reduced energy consumption at the network edge.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12061887B2Radio access network application deployment
Publication Date: 2024.08.13 NOKIA TECHNOLOGIES OY
  • US12061887B2 patent drawing
  • US12061887B2 patent drawing
  • US12061887B2 patent drawing

AI summary

According to an example aspect of the present invention, there is provided a method comprising: registering a record for a radio resource management application from an application vendor in a distributed ledger, wherein the record is cryptographically signed by the application vendor, comprises application data, and defines a deployment method for deploying the application to one or more radio access network controllers. The method further comprises transmitting, in accordance with the deployment method defined in the record, the application data to a radio access network controller for applying the application for radio resource management.