Shared Memory Isolation for Multi-Tenant Network Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data center networks face security concerns due to shared resources among multiple tenants, leading to potential unauthorized access and data breaches, especially in critical-use scenarios like public safety and healthcare applications.
Innovation Solution
Implement controlled shared memory (COSM) devices with selective read and write access to the memory device, which contact with flue gas and oxidized mercury (Hg2+) from waste liquid, adsorbing and converting Hg0 from flue gas and Hg2+ from waste liquid into stable mercury sulfide compounds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If shared memory devices are used to enable multiple tenants to access network functions, then resource utilization and productivity are improved, but security and reliability deteriorate due to potential unauthorized access and data breaches
Solution Approach 1:
The patent implements memory segmentation by dividing the shared memory device into multiple isolated memory regions, each assigned to a specific tenant. The memory management circuitry maintains separate address spaces and access permissions for each tenant, ensuring that Tenant A cannot access Tenant B's data while both share the same physical memory device. This segmentation resolves the contradiction by enabling high resource utilization through sharing while maintaining security through isolation.
Solution Approach 2:
The patent introduces memory management circuitry as an intermediary between multiple tenants and the shared memory device. This intermediary component enforces access control policies, validates memory access requests, and manages address translation. The intermediary ensures that each tenant can only access authorized memory regions, thereby maintaining security while allowing efficient shared access to the memory resource.
2Reliability
If network functions are isolated into separate physical infrastructure for each tenant, then security and reliability are improved, but device complexity and cost increase
Solution Approach 1:
The patent merges multiple isolated network functions into a single shared physical infrastructure by implementing virtualization at the memory level. Multiple tenants' network functions (e.g., CU-CP, CU-UP, DU) are consolidated on one memory device with enforced isolation through memory segmentation. This approach achieves the security of separate infrastructure while reducing the complexity and cost of deploying multiple physical systems.
Solution Approach 2:
The patent makes the shared memory device universal by enabling it to serve multiple tenants and multiple network functions simultaneously. The memory management circuitry configures the same physical memory device to provide isolated access to different tenants based on their specific requirements, eliminating the need for dedicated infrastructure for each function and reducing overall system complexity.
3Reliability
If selective read and write access control is implemented on shared memory, then security is improved, but device complexity and operational overhead increase
Solution Approach 1:
The patent implements self-service memory management where the memory management circuitry automatically handles access control decisions based on pre-configured tenant permissions. The system autonomously validates each memory access request, translates virtual addresses to physical addresses, and enforces isolation policies without requiring manual intervention. This automation reduces operational overhead while maintaining strong security controls.
Data Source
AI summary
Examples described herein include shared reserved memory regions providing communications among network functions for isolation among network slices. In some examples, a previously deployed network function can be utilized based on a level of memory region isolation of the previously deployed network function. However, if a previously deployed network function does not have a specified level of memory region isolation, another network function can be deployed with sufficient level of memory isolation can be deployed.


