Shared Reserved Memory Allocation for Isolated ORAN CU-DU Communications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network infrastructure sharing among multiple tenants introduces security concerns as traffic processed by a tenant may be accessible by another tenant, compromising data integrity and compliance with regulatory requirements, especially in critical-use scenarios like public safety and defense.
Innovation Solution
Implementing a controlled shared memory (COSM) management system that utilizes a two-level isolation mechanism to segregate memory access among tenants, ensuring secure and compliant data handling through dynamic resource allocation based on quality of service (QoS) and service level agreement (SLA) parameters, and incorporating self-destructive memory buffers to prevent data persistence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network infrastructure is shared among multiple tenants, then resource utilization and productivity are improved, but security and data integrity deteriorate due to unauthorized access risks
Solution Approach 1:
The patent divides the shared memory space into isolated segments using Control-Store-Status-Map (CSSM) registers, where each tenant's data is stored in a separate memory region that cannot be accessed by other tenants. This segmentation allows multiple tenants to share the same physical infrastructure while maintaining strict access boundaries, thus improving resource utilization without compromising security.
Solution Approach 2:
The patent introduces CSSM registers as an intermediary layer between tenants and the shared memory. These registers act as mediators that control and monitor access to memory regions, enabling secure multi-tenant operations by filtering and managing access requests without requiring direct tenant-to-tenant communication or trust.
2Device complexity
If memory resources are shared among network functions, then device complexity is reduced, but harmful factors increase due to potential data leakage and unauthorized access
Solution Approach 1:
The patent segments the shared memory into isolated regions with dedicated CSSM registers for each tenant, reducing the need for complex external security management systems while preventing data leakage through hardware-enforced access controls.
Solution Approach 2:
The CSSM registers provide self-service security management by automatically controlling access to memory regions based on predefined permissions, eliminating the need for complex external security policies and reducing the infrastructure's overall complexity while maintaining security.
3Reliability
If isolated memory regions are implemented for each tenant, then security is improved, but device complexity and resource allocation complexity increase
Solution Approach 1:
The CSSM register structure provides universal functionality for managing multiple tenants' memory access rights using a consistent register format and control mechanism. This multi-functional approach simplifies memory management complexity by applying the same isolation framework to all tenants rather than requiring tenant-specific management logic.
4Adaptability or versatility
If dynamic resource allocation is implemented based on QoS and SLA, then adaptability is improved, but device complexity and control complexity increase
Solution Approach 1:
The patent enables dynamic resource allocation by allowing CSSM register configurations to be modified at runtime based on QoS and SLA requirements. This dynamic capability allows the system to adapt resource allocation to changing conditions while the standardized register interface keeps management complexity manageable through automation and policy-based control.
Data Source
AI summary
Examples described herein include shared reserved memory regions providing communications among network functions for isolation among network slices. In some examples, circuitry is configured to: based on receipt of a first request, allocate a first region of one or more memory regions of a memory to store data reserved for access by a first network slice for communication between an Open Radio Access Network (ORAN) Centralized Unit (CU) and a Distributed Unit (DU) of the first network slice; report telemetry data indicative of access to the first region; and based on a first command, selectively adjust resources of the memory allocated to the first network slice.


