Remote Kernel Space Execution for Secure Device Maintenance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication systems face challenges in achieving good performance and efficient communication between devices, particularly in scenarios where service providers need to remotely access and control customer-premises equipment while ensuring privacy and security.

Innovation Solution

The implementation of a method and system that allows service providers to remotely execute computer instructions in the kernel space of communication devices, using an application server to send encrypted packages with instructions to the kernel space for execution, thereby enabling non-intrusive access and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a service provider representative visually inspects and gains operative control of the communication device, then the service provider can verify device usage and software version, but the customer loses full access to the communication device

Engineering Contradiction:
Improveservice provider controlVSAvoidcustomer access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments access control by creating distinct user space and kernel space environments. The customer operates in the user space with full access to applications, while the service provider gains controlled access only to the kernel space for monitoring and verification purposes. This segmentation allows both parties to have appropriate levels of access without conflict.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a remote execution environment that acts as an intermediary between the service provider and the communication device. This intermediary enables the service provider to execute verification instructions remotely in the kernel space without requiring physical presence or disrupting customer operations in the user space.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the service provider remotely executes instructions in the kernel space, then non-intrusive access is enabled, but system security and privacy concerns arise

Engineering Contradiction:
Improveremote accessVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system divides the communication device into user space and kernel space with clearly defined boundaries. The service provider's remote execution is confined to the kernel space, which is isolated from the customer's user space applications. This segmentation ensures that remote access for maintenance does not compromise user data security or privacy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary verification mechanisms where the service provider obtains and verifies cryptographic signatures of the remote execution instructions before execution. This preliminary validation ensures that only authorized and integrity-checked instructions are executed in the kernel space, preventing malicious code execution.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the customer has full access to the communication device, then privacy and security are maintained, but the service provider cannot perform monitoring and maintenance

Engineering Contradiction:
Improvecustomer accessVSAvoidmaintenance capability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system segments functionality by allowing the customer to maintain full access to user space applications while the service provider executes maintenance and monitoring instructions in the isolated kernel space. This segmentation enables both customer control and service provider productivity without mutual interference.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The remote execution environment serves as an intermediary that enables the service provider to perform maintenance operations without directly accessing or disrupting the customer's user space. The intermediary translates service provider maintenance requests into safe kernel space operations that do not interfere with customer applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If physical inspection is performed by service provider representative, then device control is verified, but customer operations are interrupted

Engineering Contradiction:
Improvedevice verificationVSAvoidoperational interruption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical approach of physical inspection by service provider representatives with a remote execution system. The service provider can verify device status and execute maintenance instructions remotely through the kernel space, eliminating the need for physical presence and avoiding interruption of customer operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The remote execution environment acts as an intermediary that enables verification and maintenance operations to be performed remotely without physical intervention. This intermediary allows the service provider to maintain device reliability through remote monitoring and updates while keeping customer operations uninterrupted.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250168151A1Remote Execution of Computer Instructions in a Kernel Space of a Communication Device
Publication Date: 2025.05.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250168151A1 patent drawing
  • US20250168151A1 patent drawing
  • US20250168151A1 patent drawing

AI summary

There is provided mechanisms for remote execution of computer instructions in a kernel space of a communication device. A method is performed by an application server for the communication device. The method comprises obtaining computer instructions for handling interaction between the application server and the kernel space. The computer instructions are to be remotely executed in the kernel space of the communication device. The method comprises sending an encrypted package comprises the computer instructions towards the kernel space of the communication device.