Shared Radio Unit Access Isolation for Multi-Operator Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Open Radio Access Network (O-RAN) standard fails to ensure private data isolation between different operators using a shared radio unit, leading to a risk of configuration interference and unauthorized modifications.
Innovation Solution
A management system for a shared radio unit that creates separate user groups for operators, divides resources into public and private sections, and binds each group to specific private resources, enabling fine-grained permission control through account passwords and data model language databases.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If different operators use the same data model to configure Shared RU, then resource utilization efficiency is improved, but data isolation and security are compromised
Solution Approach 1:
The patent segments the unified data model into operator-specific namespaces by introducing a operator_id field that divides the configuration space into isolated segments. Each operator's configuration data is tagged with their unique identifier, enabling logical separation while maintaining physical coexistence in the same Shared RU infrastructure.
Solution Approach 2:
The patent introduces an intermediary management mechanism that mediates between multiple operators and the shared radio unit. This intermediary layer enforces access control policies, validates configuration requests, and ensures that operator-specific modifications do not interfere with other operators' configurations, thus maintaining security while enabling shared access.
2Ease of operation
If operators can freely modify configuration data, then operational flexibility is improved, but configuration security and integrity are compromised
Solution Approach 1:
The patent implements preliminary action by pre-defining operator-specific namespaces and access control policies before configuration modifications occur. The system pre-establishes which operators can modify which parameters within their designated namespaces, preventing unauthorized modifications before they can occur while still allowing legitimate operational flexibility.
Solution Approach 2:
The patent incorporates feedback mechanisms that monitor configuration modification requests in real-time. The system provides feedback by validating each modification request against operator permissions, notifying operators of unauthorized access attempts, and logging all configuration changes to ensure integrity while maintaining operational flexibility for authorized users.
Data Source
AI summary
In a management method and system for a shared radio unit and a computer-readable storage medium, N user groups are created for N operators, where N is a positive integer greater than 1; resources of the shared radio unit are divided into public resources and N private resources; the N user groups and the N private resources are bound correspondingly, and the N user groups are set to only have access to corresponding private resources bound in the N private resources; resource permissions of the shared radio unit are initialized, and account passwords configured for the N user groups are sent to the corresponding N operators respectively; and the N operators configures parameters to a data model language database according to the account passwords.

