Trusted 5G Network Slices Using Trusted Execution Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
5G mobile networks face challenges in ensuring secure and trusted network slices to meet the high expectations of enterprise customers for low latency, dense device connectivity, and high-performance capabilities, particularly in managing critical business operations.
Innovation Solution
Implementing a trust model for 5G network slices using trusted computing hardware distributed across the network infrastructure, including radio access networks and cloud networks, with cryptographic sealing and unsealing of data to ensure only authenticated and authorized access, and employing trusted execution environments to secure both data and control planes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional rich execution environments (REE) are used for network slices, then device complexity and cost are reduced, but security and data integrity are compromised
Solution Approach 1:
The system segments the execution environment into two distinct parts: a trusted execution environment (TEE) for security-critical operations and a rich execution environment (REE) for general-purpose computing. This segmentation allows security-sensitive functions to run in isolated, hardware-protected TEEs while maintaining the cost-effectiveness of REE for non-critical operations, thus resolving the contradiction between security and device complexity.
Solution Approach 2:
The patent introduces TEEs as intermediary components that mediate between the untrusted REE and sensitive data/operations. The TEE acts as a secure buffer that verifies and protects data exchanges, allowing the system to leverage the simplicity of REE while maintaining security through the intermediary TEE layer, thereby resolving the contradiction between security requirements and device complexity.
2Reliability
If trusted execution environments (TEE) are deployed across distributed infrastructure, then security and data integrity are improved, but system complexity and deployment difficulty increase
Solution Approach 1:
The patent implements a universal TEE architecture that can be deployed across diverse hardware platforms and network infrastructure components. The TEE provides consistent security functionality whether deployed in RAN nodes, core network elements, or cloud infrastructure, allowing the same security model to protect data integrity across the entire distributed system without requiring platform-specific implementations, thus reducing deployment complexity.
Solution Approach 2:
The system implements measurement and attestation mechanisms that provide continuous feedback about the trust state of TEEs in the distributed infrastructure. This feedback enables automated verification of TEE integrity and configuration compliance, reducing the operational complexity of managing distributed trusted hardware by providing visibility and automated verification capabilities.
3Reliability
If cryptographic sealing is implemented for data protection, then security is improved, but processing overhead and latency increase
Solution Approach 1:
The system performs cryptographic sealing operations in advance when data is generated or received, binding the data to the TEE and slice configuration before transmission or processing. This preliminary sealing action eliminates the need for repeated encryption/decryption operations during data processing, reducing processing overhead and latency while maintaining security.
Solution Approach 2:
The TEE performs self-verification of slice configuration and data binding through automated measurement and attestation processes. This self-service capability eliminates the need for external verification mechanisms, reducing processing overhead and enabling faster security checks that maintain low latency while ensuring data integrity.
Data Source
AI summary
Slice control elements in a 5G slicing framework are instantiated in trusted hardware to provide for sealed data transmission in a trusted slice. In addition to sealing the data plane in the trusted slice, the control plane for the slice may be secured by the instantiation into the trusted hardware of layer 2 (medium access control—MAC) scheduling functions for radio resources (e.g., subcarriers and time slots). Layer 1 (physical—PHY) may also be configured to further enhance security of the trusted slice by isolating its PHY layer from that of other trusted and non-trusted slices. Such isolation may be implemented, for example, by using dedicated PHY resources, or by limiting resource time sharing to provide temporal isolation.


