Flexible Software-Defined RAN Capsules for Secure Low-Latency Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software-defined radio access network (RAN) architectures face challenges in flexibility, scalability, and efficiency due to inflexible microservice designs that fail to meet the stringent delay requirements of wireless communication, and they lack effective security mechanisms against cyber threats in multi-vendor environments.

Innovation Solution

A flexible software-defined RAN architecture utilizing capsules, modules, and liquidity controllers for dynamic composition and migration, enabling real-time adaptability, fault management, and enhanced security through detection and mitigation capsules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional microservice designs are used in RAN architecture, then system flexibility and scalability are improved, but delay requirements and response time deteriorate

Engineering Contradiction:
Improvesystem flexibilityVSAvoiddelay requirement
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The RAN architecture is segmented into multiple independent capsules (control plane capsule, user plane capsule, security capsule, fault management capsule) that can operate autonomously in parallel. This segmentation allows critical functions to be processed independently, reducing inter-service communication delays while maintaining overall system flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security capsules and fault management capsules perform security checks and fault detections in advance before main processing operations. This preliminary action prevents security threats and faults from propagating through the system, reducing response time for critical issues.

Inventive Principle:
Principle #10Preliminary action

2Stability of the object's composition

If traditional RAN architecture is used, then system stability is maintained, but security against cyber threats and adaptability to multi-vendor environments deteriorate

Engineering Contradiction:
Improvesystem stabilityVSAvoidsecurity mechanism
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

Security capsules act as intermediary components between different RAN functions and external networks. These dedicated security capsules perform authentication, authorization, and encryption/decryption operations, isolating security-critical operations from main processing paths and providing standardized security mechanisms that work across multi-vendor environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security capsules implement universal security mechanisms that can handle multiple types of threats and support various communication standards. This allows the same security infrastructure to serve multiple vendors and functions, improving adaptability while maintaining stable security operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If more security mechanisms are added to RAN, then security protection is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security functions are segmented into dedicated security capsules rather than being distributed across multiple general-purpose services. This segmentation consolidates security-related code and data structures in specific locations, making the system easier to manage and maintain despite the added security complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security capsules perform self-configuration and self-management of security parameters. The capsules automatically handle key management, certificate validation, and security policy enforcement without requiring extensive manual configuration, reducing operational complexity.

Inventive Principle:
Principle #25Self-service

4Productivity

If dynamic capsule migration is implemented, then resource utilization and adaptability are improved, but system complexity and fault detection difficulty increase

Engineering Contradiction:
Improveresource utilizationVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The fault management capsule continuously monitors capsule states and migration events, receiving feedback about system conditions. This feedback mechanism automatically triggers appropriate actions such as migration, replication, or failure recovery, managing system complexity through automated control loops rather than manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The fault management capsule acts as an intermediary that abstracts the complexity of capsule migration and state management from other RAN functions. It handles the coordination of migration events, state synchronization, and fault detection, isolating complexity to a dedicated management component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12356196B2Security in a flexible software-defined radio access network architecture and methods for use therewith
Publication Date: 2025.07.08 ISN SP ZOO
  • US12356196B2 patent drawing
  • US12356196B2 patent drawing
  • US12356196B2 patent drawing

AI summary

A RAN system includes Capsules that operate in parallel to cooperatively perform RAN stack operations, each capsule utilizing a processor and a memory configured to perform a component of the RAN stack operations, wherein a first subset of plurality of capsules is implemented by a first module under control of a first liquidity controller, wherein a second subset of capsules is implemented by a second module under control of a second liquidity controller, and wherein the first subset of capsules are mutually exclusive of the second subset of capsules. The RAN system migrates, via the first liquidity controller and the second liquidity controller, a first capsule from the first subset of capsules to the second subset of capsules as part of a security mechanism in response to a security attack on the RAN.