Secured Network Architecture for Fronthaul Transport

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communications networks, particularly in fronthaul transport, face security vulnerabilities at the Ethernet MAC layer and IP layer, with existing solutions like IEEE 802.1X and IPsec not adequately addressing threats such as denial-of-service attacks and unauthorized access, due to high processing costs and complexity in implementing MACsec and IPsec protocols.

Innovation Solution

The implementation of a secure network architecture that uses X.509v3 digital certificates for mutual authentication via IEEE 802.1X and IEEE 802.1AR, limits MAC addresses, divides traffic types, creates virtual ports with MACsec or IPsec secure connectivity associations, and maintains operator-programmable security policies, with optional TLS for additional protection, to adapt to different fronthaul scenarios and reduce processing requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec and IPsec protocols are implemented to secure network communications, then network security is improved, but processing cost and system complexity increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network traffic into different types (user plane, control plane, synchronization plane, management plane) and applies security protocols selectively to each type. This allows MACsec or IPsec to be implemented only where necessary, reducing overall processing complexity while maintaining security for critical traffic types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different security measures to different traffic types and network planes. For example, control plane traffic may receive full MACsec/IPsec protection while user plane traffic uses lighter security mechanisms, optimizing the balance between security and processing overhead.

Inventive Principle:
Principle #3Local quality

2Reliability

If MACsec and IPsec protocols are implemented to secure network communications, then network security is improved, but processing cost increases

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing cost
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments network traffic into different types and applies security protocols selectively to each type. This allows MACsec or IPsec to be implemented only where necessary, reducing overall processing cost while maintaining security for critical traffic types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by implementing security measures only for specific traffic types and network planes rather than uniformly across all traffic. This reduces processing cost by avoiding unnecessary security operations on traffic that does not require full security protection.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If IEEE 802.1X port based authentication is implemented with multiple MAC addresses, then network access flexibility is improved, but security control becomes more difficult

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-configuring security policies and authentication rules for multiple MAC addresses before network access is granted. This allows the system to maintain security control by having predetermined security measures in place for each authorized MAC address, rather than making security decisions in real-time during authentication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10924470B2Secured network architecture
Publication Date: 2021.02.16 NOKIA SOLUTIONS & NETWORKS OY
  • US10924470B2 patent drawing
  • US10924470B2 patent drawing
  • US10924470B2 patent drawing

AI summary

A secure storage for an X.509v3 digital certificate is provided (301, 302). Ports of a first and second apparatus (101, 102) are mutually authenticated (303) by using 802.1X based authentication and 802.1AR certificates. Traffic types are divided (304, 305) by an operator-configurable selector function into user plane, control plane, synchronization plane, and management plane traffic types. For Ethernet transport a virtual port is created for each traffic type, and a different MACsec secure connectivity association is created for each virtual port. For Ethernet transport an operator-programmable security policy is maintained for each traffic type. For IP transport an IPsec security association is created for each traffic type, and an operator-programmable security policy is maintained for each security association. For IP transport, TLS support may be enabled for compatibility with network management traffic. A port is repeatedly re-authenticated by an operator-definable timer value.