Secured Network Architecture for Fronthaul Transport
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communications networks, particularly in fronthaul transport, face security vulnerabilities at the Ethernet MAC layer and IP layer, with existing solutions like IEEE 802.1X and IPsec not adequately addressing threats such as denial-of-service attacks and unauthorized access, due to high processing costs and complexity in implementing MACsec and IPsec protocols.
Innovation Solution
The implementation of a secure network architecture that uses X.509v3 digital certificates for mutual authentication via IEEE 802.1X and IEEE 802.1AR, limits MAC addresses, divides traffic types, creates virtual ports with MACsec or IPsec secure connectivity associations, and maintains operator-programmable security policies, with optional TLS for additional protection, to adapt to different fronthaul scenarios and reduce processing requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec and IPsec protocols are implemented to secure network communications, then network security is improved, but processing cost and system complexity increase significantly
Solution Approach 1:
The patent segments network traffic into different types (user plane, control plane, synchronization plane, management plane) and applies security protocols selectively to each type. This allows MACsec or IPsec to be implemented only where necessary, reducing overall processing complexity while maintaining security for critical traffic types.
Solution Approach 2:
The patent implements local quality by applying different security measures to different traffic types and network planes. For example, control plane traffic may receive full MACsec/IPsec protection while user plane traffic uses lighter security mechanisms, optimizing the balance between security and processing overhead.
2Reliability
If MACsec and IPsec protocols are implemented to secure network communications, then network security is improved, but processing cost increases
Solution Approach 1:
The patent segments network traffic into different types and applies security protocols selectively to each type. This allows MACsec or IPsec to be implemented only where necessary, reducing overall processing cost while maintaining security for critical traffic types.
Solution Approach 2:
The patent applies partial action by implementing security measures only for specific traffic types and network planes rather than uniformly across all traffic. This reduces processing cost by avoiding unnecessary security operations on traffic that does not require full security protection.
3Adaptability or versatility
If IEEE 802.1X port based authentication is implemented with multiple MAC addresses, then network access flexibility is improved, but security control becomes more difficult
Solution Approach 1:
The patent implements preliminary action by pre-configuring security policies and authentication rules for multiple MAC addresses before network access is granted. This allows the system to maintain security control by having predetermined security measures in place for each authorized MAC address, rather than making security decisions in real-time during authentication.
Data Source
AI summary
A secure storage for an X.509v3 digital certificate is provided (301, 302). Ports of a first and second apparatus (101, 102) are mutually authenticated (303) by using 802.1X based authentication and 802.1AR certificates. Traffic types are divided (304, 305) by an operator-configurable selector function into user plane, control plane, synchronization plane, and management plane traffic types. For Ethernet transport a virtual port is created for each traffic type, and a different MACsec secure connectivity association is created for each virtual port. For Ethernet transport an operator-programmable security policy is maintained for each traffic type. For IP transport an IPsec security association is created for each traffic type, and an operator-programmable security policy is maintained for each security association. For IP transport, TLS support may be enabled for compatibility with network management traffic. A port is repeatedly re-authenticated by an operator-definable timer value.


