Infrastructure Equipment Baseband Encryption for Shared 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G wireless communications networks lack secure protection for proprietary baseband functions and sensitive data traffic when shared between different operators, as existing security measures do not encrypt PHY signalling, MAC header information, MAC-control elements, RLC-control packet data units, and PDCP control PDUs, risking exposure of proprietary configurations and customer data.
Innovation Solution
Implementing a method where infrastructure equipment forms a wireless access point by performing baseband functions, including encryption and decryption of packet data, to secure the transmission and reception of data between radio equipment and infrastructure equipment, using a distributed unit (DU) to create a secure environment for shared baseband processing, ensuring that sensitive information remains protected across different network operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If baseband functions are shared between different operators to improve resource utilization and reduce costs, then productivity and cost efficiency are improved, but security and confidentiality of proprietary configurations and customer data deteriorate
Solution Approach 1:
The patent segments the baseband processing functions into virtualized network functions (VNFs) that can be independently deployed and managed. This segmentation allows different operators' baseband functions to run in isolated virtual environments on shared infrastructure, maintaining security boundaries while enabling resource sharing. The segmentation of protocol stack processing into separate functional blocks further enhances this isolation capability.
Solution Approach 2:
The patent introduces a security intermediary layer that mediates between shared infrastructure resources and operator-specific baseband functions. This intermediary implements encryption and security policies that protect proprietary configurations and customer data while allowing multiple operators to share the same physical infrastructure. The security layer acts as a trusted mediator that enables resource sharing without compromising confidentiality.
2Reliability
If encryption is applied to packet data transmitted between radio equipment and infrastructure equipment to improve security, then data confidentiality is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent implements preliminary encryption of packet data at the source (radio equipment or infrastructure equipment) before transmission over the interface. By performing encryption in advance, the patent ensures data confidentiality without requiring complex real-time security processing during data transmission. The encryption keys and algorithms are pre-configured, reducing runtime complexity.
Solution Approach 2:
The patent employs parameter changes by selecting appropriate encryption algorithms and key lengths based on security requirements and processing capabilities. This allows the system to balance security strength with processing complexity, adjusting encryption parameters to match the available computational resources while maintaining adequate data protection.
Data Source
AI summary
An infrastructure equipment forms a wireless access point of a wireless communications network and executes program code that performs a plurality of processes which form a protocol stack for providing, in combination with a radio equipment, a wireless access interface of the wireless communications network for transmitting data to or receiving data from one or more communications devices. The plurality of processes provide at least a physical, PHY, layer, a medium access control, MAC, layer, a radio link control, RLC layer, a scheduler and radio resource management for the wireless access interface which together form baseband functions. The infrastructure equipment is configured to transmit/encrypt and receive/decrypt packet data. An infrastructure equipment can be shared between two wireless communications networks, which may be controlled by different operators. One or more of the plurality of processes may also be encrypted.


