Dynamic Vendor Access Control for Private 5G Fault Triage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing private 5G networks is challenging due to the complexity of integrating components from multiple third-party vendors, with existing solutions lacking adequate fault detection and secure access mechanisms for vendors to triage and remediate issues within the network.

Innovation Solution

A cloud-based fault management system that provides dynamically restricted access using a role-based access control scheme, creating a time-bound user account for third-party vendors to access specific network components for triage and remediation, ensuring minimal access necessary for problem resolution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If third-party vendors are granted full access to the tenant network for fault triage, then fault detection and remediation capabilities are improved, but network security and data protection are compromised

Engineering Contradiction:
Improvefault triage capabilityVSAvoidnetwork security risk
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The network access is segmented into multiple isolated environments (production network, test network, sandbox) with different access levels. Vendors are granted access only to specific segments necessary for their fault triage tasks, rather than providing full network access. This segmentation allows fault detection capabilities while maintaining network security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network management system acts as an intermediary between vendors and the tenant network. This intermediary controls and monitors vendor access, providing necessary fault triage capabilities while enforcing security policies and preventing direct access to sensitive network resources. The intermediary mediates between the need for vendor access and network security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple vendor components are integrated in the private 5G network, then network flexibility and scalability are improved, but system complexity and integration difficulty increase

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network management system provides universal functionality for managing multiple vendor components through a single unified interface. It handles fault detection, access control, and remediation across diverse RAN components from different vendors, eliminating the need for separate management systems for each vendor and reducing overall integration complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The complex integration and coordination functions are extracted from the vendor components and centralized in the network management system. This extraction allows individual vendor components to remain simple and focused on their core functions, while the management system handles the complexity of integrating multiple vendors' components into a cohesive private 5G network.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If vendor access to the tenant network is restricted, then network security is improved, but fault triage efficiency and problem resolution speed decrease

Engineering Contradiction:
Improvenetwork securityVSAvoidfault resolution time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

Vendor access restrictions are made dynamic rather than static. The network management system can adjust access levels, granted permissions, and isolated environment configurations based on the specific fault being triaged and the vendor's credentials. This dynamic access control maintains security while enabling efficient fault resolution when appropriate access is granted.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by pre-configuring isolated test networks and sandboxes with necessary resources and configurations before vendor access is needed. When a fault occurs, vendors can immediately access these pre-prepared environments for triage without waiting for security approvals or network configurations, reducing fault resolution time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11902804B2Fault triage and management with restricted third-party access to a tenant network
Publication Date: 2024.02.13 CISCO TECHNOLOGY INC
  • US11902804B2 patent drawing
  • US11902804B2 patent drawing
  • US11902804B2 patent drawing

AI summary

The present technology is directed to providing fault management with dynamic restricted access in a tenant network. The tenant network can be a private 5G cellular network or other wireless communication network. The present technology can identify a fault event within the tenant network based on received telemetry data, associate the fault event with a vendor component included in the tenant network, and generate a vendor fault context. The vendor fault context can be generated to include only the portion of telemetry data that is determined to be related to the fault event or the vendor component. The present technology can further use the vendor fault context to create a time-bound user account for remotely accessing the tenant network for fault triage and management. The time-bound user account can be associated to a static role-based access control (RBAC) scheme configured with access restrictions determined based on the vendor fault context.