Shared Memory Isolation for Multi-Tenant Network Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data center networks face security concerns due to shared resources among multiple tenants, leading to potential unauthorized access and data breaches, especially in critical-use scenarios like public safety and healthcare applications.

Innovation Solution

Implement controlled shared memory (COSM) devices with selective read and write access to the memory device, which contact with flue gas and oxidized mercury (Hg2+) from waste liquid, adsorbing and converting Hg0 from flue gas and Hg2+ from waste liquid into stable mercury sulfide compounds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If shared memory devices are used to enable multiple tenants to access network functions, then resource utilization and productivity are improved, but security and reliability deteriorate due to potential unauthorized access and data breaches

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements memory segmentation by dividing the shared memory device into multiple isolated memory regions, each assigned to a specific tenant. The memory management circuitry maintains separate address spaces and access permissions for each tenant, ensuring that Tenant A cannot access Tenant B's data while both share the same physical memory device. This segmentation resolves the contradiction by enabling high resource utilization through sharing while maintaining security through isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces memory management circuitry as an intermediary between multiple tenants and the shared memory device. This intermediary component enforces access control policies, validates memory access requests, and manages address translation. The intermediary ensures that each tenant can only access authorized memory regions, thereby maintaining security while allowing efficient shared access to the memory resource.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network functions are isolated into separate physical infrastructure for each tenant, then security and reliability are improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple isolated network functions into a single shared physical infrastructure by implementing virtualization at the memory level. Multiple tenants' network functions (e.g., CU-CP, CU-UP, DU) are consolidated on one memory device with enforced isolation through memory segmentation. This approach achieves the security of separate infrastructure while reducing the complexity and cost of deploying multiple physical systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the shared memory device universal by enabling it to serve multiple tenants and multiple network functions simultaneously. The memory management circuitry configures the same physical memory device to provide isolated access to different tenants based on their specific requirements, eliminating the need for dedicated infrastructure for each function and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If selective read and write access control is implemented on shared memory, then security is improved, but device complexity and operational overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidmemory management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service memory management where the memory management circuitry automatically handles access control decisions based on pre-configured tenant permissions. The system autonomously validates each memory access request, translates virtual addresses to physical addresses, and enforces isolation policies without requiring manual intervention. This automation reduces operational overhead while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250392984A1Technologies for utilizing isolated network functions
Publication Date: 2025.12.25 INTEL CORP
  • US20250392984A1 patent drawing
  • US20250392984A1 patent drawing
  • US20250392984A1 patent drawing

AI summary

Examples described herein include shared reserved memory regions providing communications among network functions for isolation among network slices. In some examples, a previously deployed network function can be utilized based on a level of memory region isolation of the previously deployed network function. However, if a previously deployed network function does not have a specified level of memory region isolation, another network function can be deployed with sufficient level of memory isolation can be deployed.