Resistance to side-channel attacks on 5G network slices

    公开(公告)号:US12219358B2

    公开(公告)日:2025-02-04

    申请号:US17448041

    申请日:2021-09-17

    Abstract: Resistance to vulnerabilities from timing-based side-channel attacks on 5G network slices that share underlying physical infrastructure and resources may be enhanced by selectively imposing time-based constraints on service provisioning and data handling to obscure data-driven time variations that occur during workload execution in a slice that can leak secret information. By preventing timing leakage from the 5G network slices, an attacker cannot observe execution latencies to thereby infer the constituency of workload characteristics. In addition, the attacker cannot create contention for shared resources on its own slice to observe an extent to which the shared resources are utilized by a targeted slice.

    Performing deep packet inspection in a software defined wide area network

    公开(公告)号:US12177130B2

    公开(公告)日:2024-12-24

    申请号:US18224466

    申请日:2023-07-20

    Applicant: VMware LLC

    Abstract: Some embodiments provide a method for performing deep packet inspection (DPI) for an SD-WAN (software defined, wide area network) established for an entity by a plurality of edge nodes and a set of one or more cloud gateways. At a particular edge node, the method uses local and remote deep packet inspectors to perform DPI for a packet flow. Specifically, the method initially uses the local deep packet inspector to perform a first DPI operation on a set of packets of a first packet flow to generate a set of DPI parameters for the first packet flow. The method then forwards a copy of the set of packets to the remote deep packet inspector to perform a second DPI operation to generate a second set of DPI parameters. In some embodiments, the remote deep packet inspector is accessible by a controller cluster that configures the edge nodes and the gateways. In some such embodiments, the method forwards the copy of the set of packets to the controller cluster, which then uses the remote deep packet inspector to perform the remote DPI operation. The method receives the result of the second DPI operation, and when the generated first and second DPI parameters are different, generates a record regarding the difference.

    COMMUNICATION SYSTEM AND COMMUNICATION CONTROL APPARATUS

    公开(公告)号:US20240323746A1

    公开(公告)日:2024-09-26

    申请号:US18578805

    申请日:2021-10-12

    CPC classification number: H04W28/0236 H04L47/225

    Abstract: A communication system including one or more base stations that accommodates wireless terminals, one or more transfer apparatuses that transfer uplink communication of the wireless terminal received via the base station to an upper side, and a transfer apparatus controller that controls the one or more transfer apparatuses includes an information acquisition unit that acquires information on wireless communication between the base station and the wireless terminal for each traffic flow, a rate determination unit that determines a shaping rate of the traffic shaping for each traffic flow, so that delay jitter in the base station is mitigated on an upper side with respect to the base station, on the basis of the information on the wireless communication for each traffic flow, and a communication control unit that executes traffic shaping on the upper side with respect to the base station on the basis of the shaping rate determined by the rate determination unit.

    Leveling HSM Service with Network Traffic Control

    公开(公告)号:US20240259287A1

    公开(公告)日:2024-08-01

    申请号:US18103568

    申请日:2023-01-31

    CPC classification number: H04L43/0888 H04L43/062 H04L47/22 H04L47/621

    Abstract: Provided is a method for a Hardware Security Module (HSM) appliance to provide cryptographic services to multiple clients via cryptographic service requests and responses transmitted over a secure communication channel there between. The method comprises the steps of providing a traffic control feature for communications over said secure communication channel by way of a Linux Kernel, and leveling cryptographic service and balancing a workload of cryptographic transactions on the HSM appliance for the multiple clients submitting said requests and receiving said responses by way of a Traffic Control Agent (TCA), thereby distributing a fair, proportional share of resources on the HSM appliance needed for servicing the cryptographic services to multiple clients irrespective of thread count per client. Other embodiments disclosed, including a dynamic intelligent TCA.

    PROTOCOL INDEPENDENT DETERMINISTIC TRANSPORT OF DATA IN A TIME-SENSITIVE NETWORK

    公开(公告)号:US20240236005A1

    公开(公告)日:2024-07-11

    申请号:US18525978

    申请日:2023-12-01

    CPC classification number: H04L47/22 H04L41/145

    Abstract: In some examples, an apparatus for protocol independent deterministic transport of data in a time-sensitive network comprises a processor, a memory coupled to the processor, the memory configured to store program code executable by the processor, the program code comprising one or more instructions, whereby to cause the apparatus to receive synchronisation data from the network, the synchronisation data comprising a measure for a clock frequency supporting transport of deterministic data traffic over the network,



    receive multiple input packets, the input packets comprising deterministic data traffic and non-deterministic data traffic, and generate, from the multiple input packets and using the synchronisation data, a set of isochronous output packets comprising respective payloads and headers.

Patent Agency Ranking