Trusted 5G Network Slices Using Trusted Execution Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

5G mobile networks face challenges in ensuring secure and trusted network slices to meet the high expectations of enterprise customers for low latency, dense device connectivity, and high-performance capabilities, particularly in managing critical business operations.

Innovation Solution

Implementing a trust model for 5G network slices using trusted computing hardware distributed across the network infrastructure, including radio access networks and cloud networks, with cryptographic sealing and unsealing of data to ensure only authenticated and authorized access, and employing trusted execution environments to secure both data and control planes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional rich execution environments (REE) are used for network slices, then device complexity and cost are reduced, but security and data integrity are compromised

Engineering Contradiction:
Improveslice securityVSAvoidhardware trust model
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the execution environment into two distinct parts: a trusted execution environment (TEE) for security-critical operations and a rich execution environment (REE) for general-purpose computing. This segmentation allows security-sensitive functions to run in isolated, hardware-protected TEEs while maintaining the cost-effectiveness of REE for non-critical operations, thus resolving the contradiction between security and device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces TEEs as intermediary components that mediate between the untrusted REE and sensitive data/operations. The TEE acts as a secure buffer that verifies and protects data exchanges, allowing the system to leverage the simplicity of REE while maintaining security through the intermediary TEE layer, thereby resolving the contradiction between security requirements and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trusted execution environments (TEE) are deployed across distributed infrastructure, then security and data integrity are improved, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improvedata integrityVSAvoiddistributed trusted hardware
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal TEE architecture that can be deployed across diverse hardware platforms and network infrastructure components. The TEE provides consistent security functionality whether deployed in RAN nodes, core network elements, or cloud infrastructure, allowing the same security model to protect data integrity across the entire distributed system without requiring platform-specific implementations, thus reducing deployment complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements measurement and attestation mechanisms that provide continuous feedback about the trust state of TEEs in the distributed infrastructure. This feedback enables automated verification of TEE integrity and configuration compliance, reducing the operational complexity of managing distributed trusted hardware by providing visibility and automated verification capabilities.

Inventive Principle:
Principle #23Feedback

3Reliability

If cryptographic sealing is implemented for data protection, then security is improved, but processing overhead and latency increase

Engineering Contradiction:
Improveslice securityVSAvoidsealing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs cryptographic sealing operations in advance when data is generated or received, binding the data to the TEE and slice configuration before transmission or processing. This preliminary sealing action eliminates the need for repeated encryption/decryption operations during data processing, reducing processing overhead and latency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The TEE performs self-verification of slice configuration and data binding through automated measurement and attestation processes. This self-service capability eliminates the need for external verification mechanisms, reducing processing overhead and enabling faster security checks that maintain low latency while ensuring data integrity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11716627B2Trusted 5G network slices
Publication Date: 2023.08.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11716627B2 patent drawing
  • US11716627B2 patent drawing
  • US11716627B2 patent drawing

AI summary

Slice control elements in a 5G slicing framework are instantiated in trusted hardware to provide for sealed data transmission in a trusted slice. In addition to sealing the data plane in the trusted slice, the control plane for the slice may be secured by the instantiation into the trusted hardware of layer 2 (medium access control—MAC) scheduling functions for radio resources (e.g., subcarriers and time slots). Layer 1 (physical—PHY) may also be configured to further enhance security of the trusted slice by isolating its PHY layer from that of other trusted and non-trusted slices. Such isolation may be implemented, for example, by using dedicated PHY resources, or by limiting resource time sharing to provide temporal isolation.