Method and apparatus for fine-grained isolation in cn-nss domain for e2e network slicing

By receiving and mapping slice isolation strategies in the core network domain, the problem of fine-grained isolation between network slices is solved, thereby satisfying diverse isolation requirements and improving network utilization.

CN116097760BActive Publication Date: 2025-12-19ALCATEL LUCENT SHANGHAI BELL CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202080104250.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-03
Publication Date
2025-12-19
Estimated Expiration
2040-08-03

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively achieve fine-grained isolation between network slices within the core network domain, especially when E2E network slices span multiple network segments, failing to meet the diverse isolation requirements of different lessees.

Method used

A method for isolating network slices in the core network domain is provided. By receiving and mapping slice isolation policies, including network resource isolation policies and application-level isolation policies, the methods are sent to the network function management function and the network function virtualization management and orchestration function, respectively, so as to achieve the isolation of network resources and application functions.

Benefits of technology

It enables fine-grained isolation of network slices in the core network domain, meeting the diverse needs of different tenants for isolation levels and improving network utilization and service quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116097760B_ABST
    Figure CN116097760B_ABST
Patent Text Reader

Abstract

Embodiments of methods and apparatus for fine-grained isolation in a CN domain for network slicing are disclosed. A method for isolation in a CN domain for network slicing includes receiving a slice isolation policy and establishing a CN NSS isolation policy based on the slice isolation policy. When the CN NSS isolation policy includes a network resource isolation policy, the network resource isolation policy is mapped to a network resource allocation policy, where a portion related to physical resources is sent to a network function management function (NFMF) and a portion related to virtual resources is sent to a network function virtualization management and orchestration function. When the NSS isolation policy includes an application level isolation policy, the application level isolation policy is mapped to an application level policy that is sent to the NFMF.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The various example embodiments described herein generally relate to communication technology, and more particularly to communication methods and apparatuses that support fine-grained isolation of network slice subnets (NSSs) in a core network (CN) domain. BACKGROUND

[0002] Some of the abbreviations that can be found in the present specification and / or in the attached claims are defined as follows:

[0003] AN Access Network

[0004] CN Core Network

[0005] E2E End-to-End

[0006] ID Identifier

[0007] NBI Northbound Interface

[0008] NF Network Function

[0009] NFMF Network Function Management Function

[0010] NFV Network Function Virtualization

[0011] NFV-MANO NFV Management and Orchestration

[0012] NFVI Network Function Virtualization Infrastructure

[0013] NFVO Network Function Virtualization Orchestration

[0014] NR New Radio

[0015] NS Network Slice

[0016] NSMF Network Slice Management Function

[0017] NSI Network Slice Instance

[0018] NSS Network Slice Subnet

[0019] NSSMF Network Slice Subnet Management Function

[0020] NSSI Network Slice Subnet Instance

[0021] NRM Network Resource Model

[0022] PNF Physical Network Function

[0023] SDN Software Defined Network

[0024] SMF Session Management Function

[0025] TN Transport Network

[0026] VLAN virtual local area network

[0027] UPF user plane function

[0028] VNF virtualized network function

[0029] VNFCI VNF component infrastructure

[0030] VNFM virtualized network function management

[0031] VIM virtualization infrastructure manager

[0032] 5G NR is designed for a wide range of usage scenarios, which typically include enhanced mobile broadband (eMBB), massive machine type communication (mMTC), and ultra-reliable low-latency communication (uRLLC). Many usage scenarios require different types of functions and networks in terms of mobility, security, policy control, latency, coverage, reliability, etc. Therefore, network slicing has been proposed to slice one physical network into multiple virtual E2E networks to carry different types of services with different characteristics and requirements. Through network slicing, various services for different companies and industries can be provided by one physical network, and thus the network utilization is greatly improved. SUMMARY

[0033] The following provides a simplified summary of exemplary embodiments to provide a basic understanding of some aspects of various embodiments. Note that this summary is not intended to identify key features or define the scope of the embodiments, and that its sole purpose is to present some concepts in a simplified form as a prelude to the more detailed description provided below.

[0034] In a first aspect, example embodiments of a method for isolation of a network slice (NS) in a core network (CN) domain are provided. The method can include receiving a slice isolation policy for a network slice subnet (NSS) in the CN domain; and establishing, based on the slice isolation policy, a NSS isolation policy for the CN NSS, the NSS isolation policy comprising at least one of a network resource isolation policy and an application level isolation policy. In case the NSS isolation policy comprises the network resource isolation policy, the network resource isolation policy can be mapped to a network resource allocation policy comprising isolation related requirements for virtual and / or physical resources of a network service. The network resource allocation policy related to physical resources is sent to a network function management function (NFMF), and / or the resource allocation policy related to virtual resources is sent to a network function virtualization management and orchestration (NFV-MANO) function for instantiation of the network service. In case the NSS isolation policy comprises the application level isolation policy, the application level isolation policy is mapped to an application level policy comprising isolation related requirements for configuring network functions, and the application level policy is sent to the NFMF to configure one or more network functions.

[0035] In a second aspect, example embodiments of a method for network resource isolation of a network slice (NS) in a core network (CN) domain are provided. The method can include receiving, from a CN network slice subnet (NSS) management function (CN NSSMF), a request to create a network service instance and a network resource allocation policy, the policy comprising virtual resource isolation related requirements for the network service instance; in response to the request, creating the network service instance by orchestrating network functions according to the network resource allocation policy, and sending the created network service instance to the higher layer.

[0036] In a third aspect, example embodiments of a method for isolation of network resources of a network slice (NS) in a core network (CN) domain are provided. The method can include receiving, from a CN network slice subnet (NSS) management function (CN NSSMF), a network resource allocation policy for a CN NSS, the policy comprising isolation related requirements for physical resources; allocating, according to the network resource allocation policy, physical network functions (PNFs) for the CN NSS; and sending, to the CN NSSMF, an ID (identifier) of the PNFs.

[0037] In a fourth aspect, example embodiments of a method for application level isolation of a network slice (NS) in a core network (CN) domain are provided. The method can include receiving, from a CN network slice subnet (NSS) management function (CN NSSMF), an application level policy for a CN NSS, the application level policy comprising isolation related requirements for configuring network functions; and configuring at least one network function according to the application level policy.

[0038] In a fifth aspect, example embodiments of a method for monitoring network slice subnet (NSS) isolation in a core network (CN) domain are provided. The method can include receiving, from a network function virtualization management and orchestration (NFV-MANO), network resource isolation monitoring data for virtual resources of a CN NSS; receiving, from a network function management function (NFMF), network resource isolation monitoring data for physical resources of a CN NSS; receiving, from a network function virtualization and orchestration (NFC-MANO), network resource isolation monitoring data for a CN NSS; analyzing the network resource isolation monitoring data to determine whether a network resource isolation policy for the CN NSS is satisfied during operation of the CN NSS; and reporting results of the analysis of the network resource isolation monitoring data to an isolation monitoring function at a higher layer.

[0039] In a sixth aspect, example embodiments of a method for monitoring network resource isolation of a network slice subnet (NSS) in a core network (CN) domain are provided. The method can include collecting isolation monitoring data related to virtual resources of a network service instance for a CN NSS; and sending the collected isolation monitoring information to an isolation monitoring function at a higher layer.

[0040] In a seventh aspect, example embodiments of a network management unit are provided. The network management unit can include at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the network management unit to receive a slice isolation policy for a network slice subnet (NSS) in the CN domain, and establish, based on the slice isolation policy, a NSS isolation policy for the CN NSS, the NSS isolation policy including at least one of a network resource isolation policy and an application level isolation policy. In the case that the NSS isolation policy includes a network resource isolation policy, the network resource isolation policy can be mapped to a network resource allocation policy including isolation related requirements for virtual and / or physical resources of a network service. The network resource allocation policy related to physical resources can be sent to a network function management function (NFMF), and / or the network resource allocation policy related to virtual resources can be sent to a network function virtualization management and orchestration (NFV-MANO) function for instantiation of the network service. In the case that the NSS isolation policy includes an application level isolation policy, the application level isolation policy can be mapped to an application level policy including isolation related requirements for configuring a network function. The application level policy can be sent to the NFMF to configure one or more network functions.

[0041] In an eighth aspect, example embodiments of a network management unit are provided. The network management unit can comprise at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the network management unit to receive, from a CN network slice subnetwork (NSS) management function (CN NSSMF), a request to create a network service instance and a network resource allocation policy comprising isolation-related requirements for virtual resources of the network service instance, create the network service instance by orchestrating network functions according to the network resource allocation policy in response to the request, and send the created network service instance to a higher layer.

[0042] In a ninth aspect, example embodiments of a network management unit are provided. The network management unit can comprise at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the network management unit to receive, from a CN network slice subnetwork (NSS) management function (CN NSSMF), a network resource allocation policy for a CN NSS, the policy comprising isolation-related requirements for physical resources, allocate physical network functions (PNFs) for the CN NSS according to the network resource allocation policy, and send IDs (identifiers) of the PNFs to the CN NSF.

[0043] In a tenth aspect, example embodiments of a network management unit are provided. The network management unit can comprise at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the network management unit to receive, from a CN network slice subnetwork (NSS) management function (CN NSSMF), an application-level policy for a CN NSS comprising isolation-related requirements for configuring network functions, and configure at least one network function according to the application-level policy.

[0044] In an eleventh aspect, example embodiments of a network management unit are provided. The network management unit can comprise at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the network management unit to receive, from a network function virtualization management and orchestration (NFV-MANO), network resource isolation monitoring data for virtual resources of the CN NSS, receive, from a network function management function (NFMF), network resource isolation monitoring data for physical resources of the CN NSS, analyze the network resource isolation monitoring data to determine whether a network resource isolation policy for the CN NSS is satisfied during a CN NSS run, and report results of the analysis of the network resource isolation monitoring data to an isolation monitoring function at a higher layer.

[0045] In a twelfth aspect, example embodiments of a network management unit are provided. The network management unit can comprise at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the network management unit to collect isolation monitoring data related to virtual resources of a network service instance of the CN NSS, and send the collected isolation monitoring data to an isolation monitoring function at a higher layer.

[0046] In a thirteenth aspect, example embodiments of a device for isolating a network slice (NS) in a core network (CN) domain are provided. The device can comprise: means for receiving a slice isolation policy for a network slice subnet (NSS) in a CN domain; means for establishing, based on the slice isolation policy, a NSS isolation policy for the CN NSS, the NSS isolation policy comprising at least one of a network resource isolation policy and an application level isolation policy; means for, in case the NSS isolation policy comprises the network resource isolation policy, mapping the network resource isolation policy to a network resource allocation policy comprising isolation related requirements for virtual and / or physical resources for a network service; means for sending, to a network function management function (NFMF), the network resource allocation policy related to physical resources and / or to a network function virtualization management and orchestration (NFV-MANO) function, the network resource allocation policy related to virtual resources, to instantiate the network service; means for, in case the NSS isolation policy comprises the application level isolation policy, mapping the application level isolation policy to an application level policy comprising isolation related requirements for configuring a network function, and means for sending the application level policy to the NFMF to configure one or more network functions.

[0047] In a fourteenth aspect, example embodiments of a device for network resource isolation for a network slice (NS) in a core network (CN) domain are provided. The device can include means for receiving, from a CN network slice subnet (NSS) management function (CN NSSMF), a request to create a network service instance and a network resource allocation policy, wherein the network resource allocation policy comprises isolation-related requirements for virtual resources of the network service instance; means for creating, in response to the request, the network service instance by orchestrating network functions according to the network resource allocation policy; and means for sending the created network service instance to the higher layer.

[0048] In a fifteenth aspect, example embodiments of a device for network resource isolation for a network slice (NS) in a core network (CN) domain are provided. The device can include means for receiving, from a CN network slice subnet (NSS) management function (CN NSSMF), a network resource allocation policy for a CN NSS, the network resource allocation policy comprising isolation-related requirements for physical resources; means for allocating, according to the network resource allocation policy, physical network functions (PNFs) for the CN NSS; and means for sending, to the CN NSSMF, IDs (identifiers) of the PNFs.

[0049] In a sixteenth aspect, example embodiments of a device for application level isolation for a network slice (NS) in a core network (CN) domain are provided. The device can include means for receiving, from a CN network slice subnet (NSS) management function (CN NSSMF), an application level policy for a CN NSS, the application level policy comprising isolation-related requirements for configuring network functions; and means for configuring at least one network function according to the application level policy.

[0050] In a seventeenth aspect, example embodiments of a device for monitoring network slice subnet (NSS) isolation in a core network (CN) domain are provided. The device can include means for receiving, from a network function virtualization management and orchestration (NFV-MANO), network resource isolation monitoring data for virtual resources of a CN NSS; means for receiving, from a network function management function (NFMF), network resource isolation monitoring data for physical resources of the CN NS; means for analyzing the network resource isolation monitoring data to determine whether network resource isolation policies for the CN NSS are satisfied during operation of the CN NSS; and means for reporting, to an isolation monitoring function at a higher layer, results of the analysis of the network source isolation monitoring data.

[0051] In an eighteenth aspect, example embodiments of an apparatus for monitoring network resource isolation of a network slice subnet (NSS) in a core network (CN) domain are provided. The apparatus can include means for collecting isolation monitoring data related to virtual resources of a network service instance for the CN NSS; and means for sending the collected isolation monitoring information to an isolation monitoring function at a higher layer.

[0052] In a nineteenth aspect, example embodiments of a computer readable medium are provided. The computer readable medium can have instructions stored thereon, and the instructions, when executed by at least one processor of a network management element, cause the network management element to perform any of the above described methods.

[0053] Other features and advantages of the example embodiments of the present disclosure will also become apparent from the following description of the exemplary embodiments, when viewed in conjunction with the accompanying drawings, which illustrate, by way of example, the principles of the embodiments of this disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0054] Some example embodiments will now be described by way of non-limiting examples, with reference to the accompanying drawings.

[0055] Figure 1 A block diagram of an E2E network slice management architecture in which example embodiments of the present disclosure can be implemented is shown.

[0056] Figure 2 A block diagram of functions for providing E2E slice isolation network slice management according to some example embodiments is shown.

[0057] Figure 3 A block diagram of functions for providing slice isolation network slice management in a core network (CN) domain according to some example embodiments is shown.

[0058] Figure 4 An interaction diagram showing the operation of a network management function for providing isolation in the NSI creation phase according to some example embodiments is shown.

[0059] Figure 5 A schematic diagram of a network service descriptor according to some example embodiments is shown.

[0060] Figure 6 An interaction diagram showing the operation of a network management function for monitoring isolation in the phase of NSI operation according to some example embodiments is shown.

[0061] Figure 7 A flow diagram of a method for isolation in a CN domain of a network slice according to some example embodiments is shown.

[0062] Figure 8A block diagram of a device according to some example embodiments is shown.

[0063] Figure 9 A flow diagram of a method for isolation in a CN domain of a network slice according to some example embodiments is shown.

[0064] Figure 10 A block diagram of a device according to some example embodiments is shown.

[0065] Figure 11 A flow diagram of a method for isolation in a CN domain of a network slice according to some example embodiments is shown.

[0066] Figure 12 A block diagram of a device according to some example embodiments is shown.

[0067] Figure 13 A flow diagram of a method for isolation in a CN domain of a network slice according to some example embodiments is shown.

[0068] Figure 14 A block diagram of a device according to some example embodiments is shown.

[0069] Figure 15 A flow diagram of a method for isolation in a CN domain of a network slice according to some example embodiments is shown.

[0070] Figure 16 A block diagram of a device according to some example embodiments is shown.

[0071] Figure 17 A flow diagram of a method for isolation in a CN domain of a network slice according to some example embodiments is shown.

[0072] Figure 18 A block diagram of a device according to some example embodiments is shown.

[0073] Figure 19 A block diagram of a network management function according to some example embodiments is shown.

[0074] Throughout the drawings, the same or similar reference numbers indicate the same or similar elements. Duplicate descriptions of the same elements will be omitted. DETAILED DESCRIPTION

[0075] Some example embodiments are described in detail below with reference to the attached drawing figures, wherein the same or like reference numerals are used to denote the same or like elements throughout the several views. A detailed description of the embodiments is provided below with reference made to the figures.

[0076] A network slice is a logical communication network running on top of a physical network, and multiple network slices running on one physical network can share network resources. One challenge for network slices is to ensure isolation between network slices, because some tenants can need to run sensitive services in network slices that are isolated from other services to some extent. An E2E network slice spans multiple parts of a network, such as an access network (AN), a transport network (TN), and a core network (CN), and needs to ensure slice isolation in each of the AN domain, the TN domain, and the CN domain. In the following, example embodiments of network slice isolation in the CN domain will be discussed in detail, and it will be understood that some embodiments or at least a part thereof will also be applicable to the AN domain.

[0077] Figure 1 An architecture of E2E network slice management is shown, in which example embodiments of the present disclosure can be implemented. Referring to Figure 1 A network slice consumer portal 110 is provided for tenants to control and manage E2E network slices. For example, the network slice consumer portal 110 can receive a request from a tenant to create an E2E network slice, as well as a service level agreement (SLA) or service profile that specifies requirements for services to be run on the network slice, such as bandwidth, rate, latency, connectivity, mobility, etc. If an SLA is received, it can be converted into a service profile. The network slice consumer portal 110 can forward the request to create a slice and the service profile to a network slice management function (NSMF) 120 to create the slice. The tenant can also monitor and update the network slice, e.g., through the network slice consumer portal 110.

[0078] When the NSMF 120 receives a request to create a network slice and service profile, it can create a network slice instance (NSI) based on the service profile. For example, the NSMF 120 can map the service profile to a slice profile and select a network resource model (NRM) for the slice. The NSMF 120 can further decompose the slice profile into domain slice profiles and invoke domain management functions to create network slice subnets (NSSs) in respective domains based on the respective domain slice profiles. For example, the NSMF 120 can invoke a CN NSS management function (NSSMF) 130 to create a NSS instance (NSSI) in the CN domain, a TN NSSMF 140 to create a NSS instance in the TN domain, and an AN NSSMF 150 to create a NSS instance in the AN domain. It should be understood that the NSMF 120 can include a plurality of logical functions for managing and orchestrating network slice instances, such as a NS orchestration function, a NS resource module function, a NS instance inventory function, a NS management function, a NS data collection function, a NS analytics function, etc. The various functions of the NSMF 120 can be deployed as respective standalone network management units or modules, or together on the same host device. It should also be understood that the domain NSSMFs 130, 140, 150 can include a plurality of logical functions for managing and orchestrating network slice subnets in their own domains. For example, each of the domain NSSMFs 130, 140, 150 can include a NSS orchestration function, a NSS resource module function, a NSSS instance inventory function, a NSSM management function, a NSSA data collection function, a NSSC data analytics function, etc. The various functions of the domain NSSMFs 130, 140, 150 can be deployed as respective standalone network management units or modules, or together on the same host device. Figure 1 The architecture shown in FIG. 1 supports service-based interfaces (SBIs) for the functions of the NSMF 120 and the NSSMFs 130, 140, 150, and these functions, which are also referred to as functional units or modules, can be implemented using hardware or running software on hardware, or can be implemented in the form of virtual functions on a common hardware platform.

[0079] The industry has recognized that isolation is an important requirement for E2E network slicing. Isolation refers to the degree of resource sharing that a tenant can tolerate, and a tenant can need different levels of isolation. For example, some tenants can not mind sharing network resources with other tenants, while some tenants can want to use dedicated physical or logical resources for all or certain types of service data. In co-owned PCT International Patent Application PCT / CN2020 / 102006 entitled “METHOD AND APPARATUS FOR ISOLATION SUPPORT IN NETWORK SLICING” filed on July 15, 2020, which is incorporated by reference herein in its entirety, slice isolation in TN domain has been discussed. In the following, example embodiments of methods and apparatuses for isolating network slice subnets in CN domain will be discussed in detail. In some example embodiments, fine-grained isolation policies can be applied to E2E network slicing, and thus network slices can meet various isolation requirements of tenants.

[0080] Figure 2 A block diagram of functions of network slice management for providing E2E slice isolation is shown according to some example embodiments. In Figure 2 the same reference numbers are used to designate network slice management functions that are the same as or similar to the functions shown in Figure 1 and a repeated description thereof is omitted here.

[0081] Referring to Figure 2 , at the network slice layer, the NSMF 120 can include an isolation management function 122 and an isolation monitoring function 124, each of which can be deployed as an independent function or together with other functions of the NSMF 120 on the same host device. The isolation management function 122 is provided to apply isolation policies for a network slice when the network slice is created, and the isolation monitoring function 124 is provided to monitor the implementation of the slice isolation policies during the operation of the network slice.

[0082] In some embodiments, the isolation management function 122 can be configured to establish a slice isolation policy for a network slice. For example, when the NSMF 120 receives a request from the network slice consumer portal 110 to create a network slice and a service profile for the network slice, the isolation management function 122 can identify or recognize isolation requirements included in the service profile to derive or export a slice isolation policy for the network slice. The isolation management function 122 can further decompose the slice isolation policy into separate slice isolation policies for the CN NSS, TN NSS, and AN NSS. The NSMF 120 can also decompose the slice profile for the network slice into separate slice profiles for the CN NSS, TN NSS, and AN NSS. In some embodiments, the separate slice isolation policies can be included in the separate slice profiles. The separate CN / TN / AN NSS slice isolation policies and slice profiles can be sent to the CN / TN / AN-NSMF 130, 140, 150, respectively, to create the CN NSS, TN NSS, and AN NSS.

[0083] In some embodiments, the isolation monitoring function 124 can be configured to receive isolation monitoring data from the CN NSS, TN NSS, and AN NSS during operation of the network slice. The isolation monitoring function 124 can further analyze the isolation monitoring data to determine whether the slice isolation policy for the network slice was properly enforced during operation of the network slice. If it is determined that the slice isolation policy was not properly enforced, the isolation monitoring function 124 can generate an alert and, optionally, trigger a reconfiguration or re-orchestration of the network slice.

[0084] With continued reference to Figure 2At the network slice subnet (NSS) layer, the CN NSSMF 130 can include a CN isolation control function 132 and a CN isolation monitoring function 134 for supporting isolation in the CN domain, the TN NSSMF 140 can include a TN isolation control function 142 and a TN isolation monitoring function 144 for supporting isolation in the TN domain, and the AN NSSMF 150 can include an AN isolation control function 152 and an AN isolation monitoring function 154 for supporting isolation in the AN domain. The domain isolation control functions 132 / 142 / 152 can assist the domain NSSMFs 130 / 140 / 150 to create network slice subnets based on respective slice isolation policies. The domain isolation monitoring functions 134 / 144 / 154 can monitor the implementation of the slice isolation policies in the respective domains during the running of the network slice subnets. The domain isolation functions 132, 134, 142, 144, 152, 154 can be deployed as standalone network management functions or together with other functions of the respective NSSMFs at the same host device. Isolation in the TN domain has been discussed in detail with reference to the operation of the TN isolation control function 142 and the TN isolation monitoring function 144 in PCT patent application PCT / CN2020 / 102006, and the repetitive description thereof is omitted here. In the following, isolation in the CN domain will be discussed, and it will be understood that the embodiments disclosed herein are also applicable, at least in part, in the AN domain.

[0085] Figure 3 A block diagram of functions of network slice subnet management and orchestration for providing slice isolation in a core network (CN) domain is shown in accordance with some example embodiments. In the CN domain, a network function virtualization management and orchestration (NFV-MANO) 200 is provided to manage a network function virtual infrastructure (NFVI) and to orchestrate allocation of resources for network services and virtual network functions (VNFs). The NFV-MANO 200 can receive a resource allocation request for a network service from a higher layer, i.e., the CN NSSMF 130 or a NSS orchestration function therein, map the received request to an appropriate network service catalog with some network service instance requirements such as bandwidth, latency, and then confirm the resource allocation of the network service instance to the higher layer.

[0086] Reference Figure 3NFV-MANO 200 includes a network function virtualization orchestrator (NFVO) 210, virtualized network function managers (VNFM) 230, and a virtualized infrastructure manager (VIM) 240. The NFVO 210 can be responsible for orchestration of NFVI resources across multiple VIMs and lifecycle management of network services. The NFVO 210 can include a network service catalog 211, a virtualized network function (VNF) catalog 212, a network service instance repository 213, a VNF instance repository 214, a NFVI resource repository 215, a NFVO isolation capability repository 216, and a NFVO isolation monitoring function 217.

[0087] The network service catalog 211 can maintain a repository of all on-board network services that can support creation and management of network service deployment templates / resource models via interface operations exposed by the NFVO 210. The network service deployment templates / resource models can include, for example, network service descriptors (NSD), virtual link descriptors (VLD), VNF forwarding graph descriptors (VNFFGD), etc.

[0088] The VNF catalog 212 can maintain a repository of all on-board VNF packages, including VNF descriptors (VNFD), software images, manifest files, etc., that can support creation and management of VNF packages via interface operations exposed by the NFVO 210. The NFVO 210 and VNFM 230 can query the VNF catalog 212 to find and retrieve VNFDs in order to support operations such as validation and checking of instantiation feasibility.

[0089] The network service instance repository 213 includes information of all network service instances, and the VNF instance repository 214 includes information of all VNF instances. Each network service instance is represented by a network service record, and each VNF instance is represented by a VNF record. These records are updated during the lifecycle of the respective instances, reflecting changes resulting from the execution of network service lifecycle management operations and / or VNF lifecycle management operations. This supports the responsibilities of the NFVO 210 and VNFM 230 in maintaining the integrity and visibility of network service and VNF instances and their relationships.

[0090] The NFVI resource repository 215 includes information about available, reserved, and allocated NFVI resources abstracted by the VIM 240 across the network operator’s infrastructure domains, thus supporting information for resource reservation, allocation, and monitoring purposes. In this way, the NFVI resource repository 215 plays an important role in supporting the resource orchestration and management capabilities of the NFVO by allowing tracking of NFVI reserved / allocated resources with respect to the network service and VNF instances associated with these resources.

[0091] The NFVO isolation capability repository 216 maintains isolation policies that should be applied during orchestration of a network service instance. For example, the isolation policies can include network service isolation, VNF isolation, virtual compute isolation, virtual storage isolation, hardware location isolation, VNF security based isolation, virtual link isolation, etc.

[0092] The NFVO isolation monitoring function 217 is provided for monitoring isolation related data during CN NSS operation, and details thereof will be discussed later.

[0093] The VNFM 230 is provided for lifecycle management of VNF instances. The VNFM 230 can include a VNF isolation capability repository 231 that maintains isolation policies related to VNFs, including, for example, VNFCI isolation, virtual compute isolation, virtual storage isolation, geo-location isolation of hardware virtualized to provide virtual resources, VNF security based isolation, virtual link isolation, etc. The VNFM 230 can also send an ID (identifier) of a VNF to a network function management function (NFMF) 220 for service configuration of the VNF.

[0094] The NFMF 220, also referred to as an element manager (EM), is capable of application level management of physical network functions (PNFs) 222 and VNFs 223. PNFs and VNFs can be implemented as, for example, network functions in a 5G network, such as a session management function (SMF), a user plane function (UPF), an access and mobility management function (AMF), etc. The NFMF 220 can configure the functionality, service parameters, or operation of a PNF or VNF when a PNF or VNF instance is created with allocated resources. The NFMF 220 can include a PNF isolation capability repository 221 that maintains isolation policies related to PNFs, including, for example, PNF isolation, compute isolation, storage isolation, geo-location isolation, PNF security based isolation, physical network link isolation, etc. In some embodiments, the PNF isolation capability repository 221 can also maintain application level isolation policies related to PNFs and VNFs.

[0095] The VIM 240 is provided to control and manage NFVI resources, such as virtual compute resources 251, virtual storage resources 252, and virtual network resources 253. The VIM 240 can include a software defined network (SDN) control module 241 to control data traffic of the NFVI resources. The NFVI 250 can store information of available, reserved, and allocated NFVI resources abstracted by the VIM 240.

[0096] Figure 4 An interaction diagram showing operations of network management functions for providing isolation in a core network domain according to some example embodiments is shown. For better understanding, reference can be made to Figures 2-3 for reading Figure 4The following description of the interactions shown in FIG. 3.

[0097] Referring to Figure 4 The CN isolation control function 132 can receive 310 a slice isolation policy for a network slice subnet (NSS) in the CN domain from the NS layer, i.e., the NSMF 120 or the isolation management function 122 therein. In some embodiments, the CN isolation control function 132 can receive the slice isolation policy directly from the NSMF 120 or via the CN NSSFM 130. Then, the CN isolation control function 132 can establish 312 a CN NSS isolation policy based on the received slice isolation policy. According to the slice isolation policy, the CN NSS isolation policy can include a data traffic isolation policy, a network resource isolation policy, and / or an application level isolation policy. The data traffic isolation support in the TN domain has been disclosed in commonly owned PCT patent application PCT / CN2020 / 10206, and it is also applicable to the CN and AN domains. Therefore, the repetitive description of the data traffic isolation policy is omitted here.

[0098] The slice isolation policy received from the NS layer generally includes high-level isolation requirements for the CN NSS. For example, the slice isolation policy can only specify the isolation levels defined by the Global System for Mobile Communications Association (GSMA), such as no isolation, physical isolation, or logical isolation. In operation 310, the CN NSS isolation policy can be established with extended attributes considering the slice isolation policy and the slice profile received from the NS layer. The slice profile specifies the characteristics and / or requirements of the network slice to be created, such as application type, security requirement, availability, reliability, latency, mobility, etc., which can be reflected into the CN NSS isolation policy established in operation 310. For example, high-level security requirements for a network slice can correspond to high-level isolation, and a high-reliability application such as a banking service can correspond to user data isolation. Therefore, a fine-grained isolation policy can be established for the CN NSS. According to the slice isolation policy and the slice profile received from the NS layer, the CN NSS isolation policy can include a network resource isolation policy and / or an application level isolation policy. The network resource isolation policy can also include physical isolation and logical isolation. The physical isolation can include attributes such as dedicated PNF isolation, dedicated physical network link isolation, geographical location isolation, compute isolation, memory isolation, storage isolation, and PNF security-based isolation. The logical isolation can include attributes such as dedicated VNF isolation, virtual link isolation, virtual storage isolation, geographical location isolation of hardware virtualized to provide virtual resources, and VNF security-based isolation. The application level isolation policy can include attributes such as control plane isolation, data plane isolation, management plane isolation, and subscriber data isolation, which can be based on physical isolation or logical isolation. It should be understood that the isolation attributes are given here as examples, and other attributes can also be used for the CN NSS isolation policy.

[0099] Then, if VNFs are involved in the network slice, the CN NSS isolation policy is translated into a policy that can be implemented and enforced at NFV-MANO 200, and / or if PNFs are involved in the network slice, a policy that is implemented and enforced at NFMF 220. Specifically, in the case that the established CN NSS isolation policy includes a network resource isolation policy, the CN isolation control function 132 can map 314a the network resource isolation policy to a network resource allocation policy. The network resource allocation policy can include isolation related requirements for virtual and / or physical resources of the network service, and examples of the network resource allocation policy are shown in Table 1 below. As shown in Table 1, fine-grained network resource isolation policies are reflected to descriptors of the network service and the physical and logical resources involved in the network service such as PNFs, VNFs. It should be understood that Table 1 only shows a portion of physical and logical isolation, and the physical and logical isolation can include extended attributes mapped to descriptors of the network service, PNFs, and VNFs.

[0100] Table 1: Examples of network resource allocation policy

[0101]

[0102]

[0103] For better understanding of the descriptors shown in Table 1, Figure 5 A block diagram showing descriptors of the network service, PNFs, and VNFs. In Figure 5 each block shows a descriptor, whose information elements are identified as in brackets. Referring to Table 1 and Figure 5 The network service descriptor (NSD) is a network service deployment template / resource model, whose instance is used by the NFVO for lifecycle management of the network service. The NSD includes or references descriptors of its constituent objects, such as PNF descriptors, VNF descriptors, network service virtual link descriptors, forwarding graph descriptors, and network service security capability descriptors. The network service virtual link descriptor is a deployment template / resource model that describes the resource requirements needed for a link between VNFs, PNFs, and endpoints of the network service, which can be used by the NFVI 250. The forwarding graph descriptor is a deployment template / resource model that describes a topology or a part of the topology of the network service by referencing VNFs, PNFs, and virtual links connecting them. The network service security capability descriptor is a deployment template / resource model that describes security requirements of the network service such as authentication, authorization, integrity, confidentiality, data filtering, etc. It can be understood that the security capability descriptor included in the NSD will help support security-based isolation policies in the network service.

[0104] The NSD can include or reference one or more PNF and / or VNF descriptors. A PNF descriptor (PNFD) is included when a PNF is incorporated in the network service, and it describes the connectivity, interfaces, and KPI requirements of the virtual links to the PNF. The PNFD can include or reference descriptors of the provider of the PNF, the geographical location, and the point of attachment. When a VNF is involved in the network service, a VNF descriptor (VNFD) is included, and it is a deployment template / resource model according to which the VNF is deployed and its operational behavior requirements are described. The VNFD is used by the VNFM 230 in VNF instantiation and VNF instance lifecycle management. The VNFD includes or references descriptors of the software image that the VNF will use, the programming language of the VNF image, the provider of the VNF, virtual deployment units (VDUs), VNF connection types, and VNF security capabilities. The descriptor of security capabilities can include, for example, access control, confidentiality, integrity, non-repudiation, etc. The VDU descriptor is a deployment template / resource model that describes the resource requirements of a VNF component such as a virtual machine (VM), a container, etc. The VDU descriptor can include or reference descriptors of the geographical location of the hardware that is virtualized to provide virtual resources for the VNF, virtual compute resources including process scheduling to be used by the VNF such as CPU and memory, virtual storage resources to be used by the VNF, internal virtual links of the VNF, VNF virtualization technology such as VMWARE, KVM, XEN, Lxc, VirtualBox, Container, Hyper-V, and virtualization security capabilities of the VNF such as access control, integrity, confidentiality, non-repudiation, hardware security module, trusted platform module, etc.

[0105] Referring back to Table 1, in the network resource allocation policy, the network resource isolation policy is related to the NSD. Then, when the NFV-MANO 200 uses the NSD to instantiate the network service, it will allocate resources for the network service instance according to the isolation policy. Therefore, the isolation policy is applied to the network service instance created based on the NSD.

[0106] With continued reference to Figure 4In case the established CN NSS isolation policy comprises an application level isolation policy, the CN isolation control function 132 can map the application level isolation policy to an application level policy comprising isolation related requirements 314b for configuring network functions such as PNFs 222 and / or VNFs 223. PNFs 222 and VNFs 223 can be implemented as various network functions for network services such as a session management function (SMF), a user plane function (UPF), an access and mobility management function (AMF), a unified data management (UDM) function, a unified data repository (UDR) function, etc., and the application level policy can describe requirements for application level configuration of the PNFs and VNFs. For example, if the application level isolation policy comprises subscriber data isolation, the corresponding application level policy can describe that a PNF or VNF implemented as a unified data management (UDM) function or a unified data repository (UDR) function shall be configured to store subscriber data in physically or logically independent databases. For another example, if the application level isolation policy comprises user plane isolation, the corresponding application level policy can describe that a dedicated UPF shall be configured for the network service.

[0107] The CN isolation control function 132 can then send 315a a network resource allocation policy related to physical resources to the NFV-MANO 200 and send 315b a resource allocation policy related to virtual resources and / or an application level policy to the NFV-MANO 200 and / or to the NFV-MANO 200. The CN isolation control function 132 can send the policies to the NFV-MANO 200 and the NFV-MANO 200 via the CN NSSMF 130. For example, the CN NSSMF 130 can send a request to create a network service instance to the NFV-MANO 200 together with a network resource allocation policy for the network service instance.

[0108] In response to the request to create the network service instance, the NFV-MANO 200 can create the network service instance 316 by orchestrating the network functions and other components according to the network resource allocation policy. For example, the NFV-MANO 200 can allocate resources and orchestrate the network functions and other components taking into account some requirements such as bandwidth, latency of the network service instance, and network resource allocation policy for the network service instance. The orchestrated network service instance can include multiple PNF and / or VNF instances connected with links forming a service chain. If PNFs are involved in the network service, the NFV-MANO 200 can receive PNF IDs from the CN NSSMF 130 for the orcheststration of the network service instance. In some embodiments, the NFMF 220 can refer to the PNF isolation capability repository 221 to allocate 317 appropriate PNFs that comply with the received network resource allocation policy for the network service and return the IDs (identifiers) of the PNFs 318 to the CN NSSMF 130. The CN NSSMF 130 can forward the PNF IDs (identifiers) to the NFV-MANO 200 for the orchestration of the network service instance. The VNFM 230 of the NFV-MANO 200 can select existing VNF instances that comply with the network resource allocation policy for the network service with the assistance of the VNF isolation capability 231. If none of the existing VNF instances complies with the network resource allocation policy, the VNFM 230 can create a new VNF instance by allocating virtual resources for the new VNF instance. The NFV-MANO 200 creates the network service instance 316 based on the PNF and / or VNF instances and sends 319 the identifier of the created network service instance to the CN NSSMF 130 and, consequently, to the CN isolation control function 132. The NFMF 220 can configure 320 the PNFs and / or VNFs of the network service instance according to the received application level policy. The NFMF 220 can receive the IDs (identifiers) of the VNF instances from the CN NSSMF 130 or from the VNFM 230.

[0109] The CN NSSMF 130 can map 321 the network service instance to a CN NSS. For example, the CN NSSMF 130 can map an ID (identifier) of the network service instance to a single network slice selection assistance information (S-NSSAI) that uniquely identifies a CN NSS of the network slice. The CN isolation control function 132 can maintain 322 a mapping between the NSS isolation policy and the network service instance. In some embodiments, when the NSS isolation policy is shared by multiple network slices or network slice subnetworks, the CN isolation control function 132 can further check 323 whether the NSS isolation policy conflicts with other network slices or other network slice subnetworks. If a conflict is determined at operation 323, the CN isolation control function 132 can trigger 324 a reconfiguration and / or a re-orchestration of the CN NSS to eliminate the conflict. For example, if the CN NSS uses a PNF that is shared by another network slice that requires dedicated PNF isolation, the CN isolation control function 132 can trigger a re-orchestration of the CN NSS to assign a different PNF for the CN NSS.

[0110] Some examples of CN NSSs with corresponding slice isolation policies will be described here.

[0111] Example 1

[0112] The uRLLC NS consumer C1 requests to create a network slice with physical isolation. Therefore, a network slice S-NSSAI-1 is created for this NS consumer. For the CN domain, a CN network slice subnetwork CN-NSS-1 is created, in which a dedicated PNF, a dedicated network link, and VNFs deployed on a dedicated server / hypervisor are allocated.

[0113] Example 2

[0114] The eMBB NS consumer C2 requests to create a network slice with network function isolation, i.e., a kind of logical isolation. A network slice S-NSSAI-2 is created for this NS consumer. For the CN NSS domain, CN-NSS-2 is created using dedicated VNFs and virtual network links.

[0115] Example 3

[0116] The mMTC NS consumer C3 requests to create a network slice with geographical location isolation. A network slice S-NSSAI-3 is created for this NS consumer. For the CN NSS domain, CN-NSS-3 is created by PNFs, VNFs, and virtual network links that are not located in a specific location, e.g., Loc_A.

[0117] Example 4

[0118] The game service provider NS consumer C4 requests creation of an E2E network slice with logical isolation. It is assumed that CN-NSS-1, CN-NSS-2 and CN-NSS-3 have already been created. The NSMF 120 decomposes the request and invokes the CN / TN / AN NSS management functions 130, 140, 150 respectively to create the network slice subnets. The NSMF 120 also decomposes the E2E network slice isolation policy to separate the slice isolation policy for each NSS. The CN isolation control function 132 of the CN NSS domain receives the slice isolation policy and maps the slice isolation policy to a network resource isolation policy that includes “dedicated VNFs” and “dedicated virtual network links”. It is assumed that no application level isolation is needed in this example. The network slice identifier of the requested game service provider is S-NSSAI_50. With the assistance of the CN isolation control function 132, the CN NSSMF 130 decides to re-use CN-NSS-2 according to the obtained network resource isolation policy. However, both consumer C2 and the game service provider need dedicated network function isolation, so a different VNF instance should be created for the game service. Therefore, as discussed above with reference to Figure 3 CN-NSS-2 is created using a different VNF instance identifier implemented at the NFV layer.

[0119] The mapping between the network resource isolation policy and the network service descriptor of Example 1-4 is shown in Table 2.

[0120] Table 2: Mapping between network resource isolation policy and network service descriptor

[0121]

[0122]

[0123] *1: There can be one or more PNFs, but only one is shown in Table 2.

[0124] *2: There can be one or more VNFs, but only one is shown in Table 2.

[0125] Figure 6 An interaction diagram showing the operation of a network management function for monitoring isolation in a phase of network slice operation is shown in accordance with some example embodiments. For better understanding, reference can be made to Figures 2-3 for reading the following description of the interaction shown in Figure 6

[0126] When a network slice is operational to provide services for a tenant, the tenant can want to monitor the operation of the network slice to check whether the slice isolation policy is correctly enforced. In some embodiments, the network management function for monitoring isolation can be used as shown in Figure 2 ​The illustrated deployment isolates the monitoring functions at the NS and NSS layers to enable monitoring of the enforcement of isolation policies. Referring to Figure 6 The isolation monitoring function 124 at the NS layer can send 410 a request to collect isolation monitoring data to each domain isolation monitoring function at the NSS layer, including the CN isolation monitoring function 134. In response to the request 410 received from the isolation monitoring function 124, the CN isolation monitoring function 134 can send 412 a request to collect isolation monitoring data to the NFV-MANO 200, or more specifically to the NFVO isolation monitoring function 217 of the NFVO 210 included in the NFV-MANO 200, and the NFMF 220. In some embodiments, the request 410 can be omitted, and the CN isolation monitoring function 134 can periodically send the request 412 to the NFV-MANO 200 and the NFMF 220.

[0127] In response to the request 412, the NFV-MANO 200 collects 414a isolation monitoring data related to the virtual resources of the network service instances of the CN NSS, and the NFMF 220 collects 414b isolation monitoring data related to the physical resources and application level isolation requirements of the CN NS. Specifically, the NFV-MANO 200 can collect the isolation monitoring data through the NFVO 210, the VNFM 230, and the VIM 240. In some embodiments, the NFV-MANO 200, or more specifically the NFVO 210 and the VNFM 230, can pre-process 415a the collected isolation monitoring data with reference to the isolation policies maintained at the NFVO isolation capability repository 216 and the VNF isolation capability repository 231. If the collected monitoring data is not relevant to the isolation policies of the CN NSS, the NFV-MANO 200 can ignore the data. The NFV-MANO 200 can then send 416a the isolation relevant monitoring data to the CN isolation monitoring function 134, and can save bandwidth. Similarly, the NFMF 220 can also pre-process 415b the collected isolation monitoring data with reference to the isolation policies maintained at the PNF / application level isolation capability repository 221. If the collected monitoring data is not relevant to the isolation policies for the CN NSS, the NFMF 220 can ignore the data. The NFMF 220 can then send 416b the isolation relevant monitoring data to the CN isolation monitoring function 134, and can save bandwidth.

[0128] In some embodiments, the request 412 can also be omitted. The NFV-MANO 200 and the NFMF 220 can periodically collect, pre-process, and report the isolation monitoring data to the CN isolation monitoring function 134.

[0129] The CN isolation monitoring function 134 can analyze 418 the received isolation monitoring data to determine whether the network resource isolation policy and / or the application level isolation policy was correctly implemented during the CN NSS run. The CN isolation monitoring function 134 can report 422 the analysis results to the NS isolation monitoring function 124, optionally together with the original isolation monitoring data. In some embodiments, the CN isolation monitoring function 134 can also trigger 420 a reconfiguration and / or a reorchestration of the CN NSS to comply with the network resource isolation policy and / or the application level isolation policy, if it is determined at operation 418 that the network resource isolation policy and / or the application level isolation policy was not correctly implemented during the CN NSS run.

[0130] Embodiments of isolation applications and monitoring procedures in the CN NSS domain have been discussed above with reference to Figures 1-6 Fig. 1. As shown, fine-grained isolation policies including network resource isolation policies, application level isolation policies and data traffic isolation policies are well supported in the CN domain. It should be appreciated that the above embodiments can also be applied to the AN domain in a similar manner.

[0131] Figure 7 A flowchart of a method 500 for supporting isolation in a CN domain for network slicing according to some example embodiments is shown. The method 500 can be performed, for example, at a network management function unit such as the CN isolation management function 132 shown in Fig. 1. Figure 3

[0132] With reference to Figure 7 Fig. 1, the example method 500 can include a step 510 of receiving a slice isolation policy for a NSS in the CN domain and a step 520 of establishing a CN NSS isolation policy based on the received slice isolation policy.

[0133] For example, the slice isolation policy for the CN NSS can be a high-level isolation policy received in or together with the CN NSS slice profile from the NSMF 120. In step 520, the slice isolation policy is mapped to a CN NSS isolation policy with extended attributes as described above. The CN NSS isolation policy can include a network resource isolation policy and / or an application level isolation policy.

[0134] In the case of a network resource isolation policy, the method 500 can include a step 530a of mapping the network resource isolation policy to a network resource allocation policy including isolation related requirements for virtual and / or physical resources for the CN NSS. Examples of network resource allocation policies are shown in Table 1 above. In step 540a, the network resource allocation policy related to physical resources can be sent to the NFMF 220 and / or the resource allocation policy related to virtual resources can be sent to the NFV-MANO 200 for instantiation of the network service. ​

[0135] In case of network resource isolation policies, the method 500 can comprise a step 530a of mapping the network resource isolation policies to network resource allocation policies, the policies comprising isolation related requirements of virtual and / or physical resources of the CN NSS. Examples of network resource allocation policies are shown in Table 1 above. In a step 540a, the network resource allocation policies related to physical resources can be sent to the NFMF 220 and / or the resource allocation policies related to virtual resources can be sent to the NFV-MANO 200 for instantiation of the network service.

[0136] In case of application level isolation policies, the method 500 can comprise a step 530b of mapping the application level isolation policies to application level policies, the application level policies comprising isolation related requirements for configuring the network functions. The application level policies describe the application level configuration requirements of the network functions for implementing the application level isolation policies. In a step 540b, the application level policies can be sent to the NFMF 220 to configure one or more network functions.

[0137] Optionally, the method 500 can further comprise a step 550 of receiving information for the CN NSS, such as an ID (identifier) of a network service instance, from the NFV-MANO, and a step 560 of maintaining a mapping between the CN NSS isolation policies and the network service instance for the CN NSS. In some embodiments, the ID (identifier) of the network service instance can be related to the S-NSSAI of the CN NSS.

[0138] In some embodiments, the method 500 can optionally comprise a step 570 of checking whether the CN NSS isolation policies conflict with other network slices or other network slice subnetworks when the CN NSS isolation policies are shared by multiple network slices or network slice subnetworks. If a conflict is determined, the method 500 can comprise a step 580 of triggering reconfiguration and / or re-orchestration of the CN NSS to eliminate the conflict.

[0139] Figure 8 A block diagram of a device 600 is shown in accordance with some example embodiments. The device 600 can be implemented, for example, in the CN isolation control function 132 to perform the method 500 shown in Figure 7 with reference to Figure 8The device 600 can comprise a first means (or module or unit) 610 for performing step 510 of the method 500, a second means 620 for performing step 520 of the method 500, a third means 630a for performing step 530a of the method 500, a fourth means 630b for performing step 530b of the method 500, a fifth means 640a for performing step 540a of the method 500, and a sixth means 640b for performing step 540b of the method 500. Optionally, the device 600 can further comprise a seventh means 650 for performing step 550 of the method 500, an eighth means 660 for performing step 560 of the method 500, a ninth means 670 for performing step 570 of the method 500, and a tenth means 680 for performing step 580 of the method 500.

[0140] Figure 9 A flowchart of a method 700 for supporting isolation in a CN domain for network slicing is shown in accordance with some example embodiments. The method 700 can be performed, for example, at a network management function such as the NAF-MANO 200 shown in Figure 3 .

[0141] Referring to Figure 9 , the method 700 can comprise a step 710 of receiving, from the CN NSSMF 130, a request to create a network service instance and a network resource allocation policy for the network service instance. The network resource allocation policy can comprise fine-grained isolation related requirements for virtual resources of the network service instance, such as VNFs, virtual links, forwarding graphs, and security capabilities. Examples of network resource allocation policies are shown in Table 1 above. At step 720, the NAF-MANO 200 can create the network service instance by orchestrating network functions and other components for the network service in accordance with the network resource allocation policy. When PNFs are involved in the network service, the NAF-MANO 200 can also receive IDs (identifiers) of the PNFs for the orchestration of the network service. Then, at step 730, the NAF-MANO 200 sends an ID of the created network service instance to the CN NSSMF 130.

[0142] Figure 10 A block diagram of a device 800 is shown in accordance with some example embodiments. The device 800 can be implemented, for example, in the NFV-MANO 200 to perform the method 700 shown in Figure 9 . Referring to Figure 10 , the device 800 can comprise a first means (or module or unit) 810 for performing step 710 of the method 700, a second means 820 for performing step 720 of the method 700, and a third means 830 for performing step 730 of the method 700.

[0143] Figure 11A flowchart illustrating a method 900 for supporting isolation in a CN domain for network slicing according to some example embodiments is shown. The method 900 can be performed, for example, at a network management unit such as the NFMF 220 shown. Figure 3 in a network management unit such as the NFMF 220 shown.

[0144] Referring to Figure 11 , the method 900 can include a step 910 of receiving, from the CN NSSMF 130, a network resource allocation policy for a CN NSS. The received network resource allocation policy can include isolation related requirements for physical resources of the CN NSS, such as isolation requirements for providers, locations, and connection points of PNFs. At a step 920, the NFMF 220 can allocate PNFs for the CN NSS according to the network resource allocation policy, and at a step 930 return IDs (identifiers) of the PNFs to the CN NSSMF 130. The CN NSSMF 130 can forward the IDs (identifiers) of the PNFs to the NFV-MANO 200 for orchestration of the network service.

[0145] Figure 12 A block diagram illustrating a device 1000 according to some example embodiments is shown. The device 1000 can be implemented, for example, in the NFMF 220 to perform the method 900 shown in Figure 11 Referring to Figure 12 , the device 1000 can include a first means (or module or unit) 1010 for performing the step 910 of the method 900, a second means 1020 for performing the step 920 of the method 900, and a third means 1030 for performing the step 930 of the method 900.

[0146] Figure 13 A flowchart illustrating a method 1100 for supporting application level isolation in a CN domain for network slicing according to some embodiments is shown. The method 1100 can be performed, for example, at a network management unit such as the NFMF 220 shown. Figure 3 in a network management unit such as the NFMF 220 shown.

[0147] Referring to Figure 13 , the method 1100 can include a step 1110 of receiving, from the CN NSSMF 130, an application level policy for a CN NSS. The application level policy can include application level isolation related requirements for network functions such as PNFs or VNFs. At a step 1120, the NFMF 220 can configure at least one network function according to the application level policy such that the network function complies with the application level isolation requirements.

[0148] Figure 14 A block diagram illustrating a device 1200 according to some example embodiments is shown. The device 1200 can be implemented, for example, in the NFMF 220 to perform the method 1100 shown in Figure 13 Referring toFigure 14 The device 1200 can comprise a first means (or module or unit) 1210 for performing step 1110 of the method 1100 and a second means 1220 for performing step 1120 of the method 1100.

[0149] Figure 15 A flowchart of a method 1300 for monitoring isolation in a CN domain of a network slice according to some embodiments is shown. The method 1300 can be performed, for example, at a network management unit of a CN isolation monitoring function 134 of a CN NSSMF 130 as shown. Figure 3 The method 1300 can be performed, for example, at a network management unit of a CN isolation monitoring function 134 of a CN NSSMF 130 as shown.

[0150] Reference is made to Figure 15 The method 1300 can comprise a step 1310 of sending a request to collect isolation monitoring data of a CN NSS to the NFV-MANO 200 and / or the NFMF 220. The request can be sent periodically or in response to an instruction from a higher layer isolation monitoring function, e.g., the isolation monitoring function 124 at the NS layer, to collect isolation monitoring data. In some embodiments, the step 1310 can be omitted. At step 1320, the CN isolation monitoring function 134 can receive network resource isolation monitoring data related to virtual resources of the CN NSS from the NFV-MANO 220, and at step 1330, the CN isolation monitoring function 134 can receive network resource isolation monitoring information related to physical resources of the CN NSS from the NFMF 220. Optionally, at step 1340, the CN isolation monitoring function 134 can also receive application level isolation monitoring data of the CN NSS from the NFMF 220. Then at step 1350, the CN isolation monitoring function 134 can analyze the received isolation monitoring data, including the network resource isolation monitoring data related to virtual resources, the network resource isolation monitoring information related to physical resources, and / or the application level isolation monitoring data of the CN NSS, to determine whether a CN NSS isolation policy including a network resource isolation policy and / or an application level isolation policy is properly implemented during the network slice operation. At step 1360, the CN isolation monitoring function 134 can report the analysis result, optionally together with the initial isolation monitoring data, to a higher layer isolation monitoring function, e.g., the isolation monitoring function 124 at the NS layer. Optionally, if it is determined at step 1350 that the CN NSS isolation policy is not properly implemented during the network slice operation, the CN isolation monitoring function 134 can also trigger reconfiguration and / or re-orchestration of the CN NSS to comply with the CN NSS isolation policy.

[0151] Figure 16 A block diagram of a device 1400 according to some example embodiments is shown. The device 1400 can be implemented, for example, in the CN isolation monitoring function 134 to perform the method 1300 as shown. Figure 15 Reference is made toFigure 15 The device 1400 may include a first means (or module or unit) 1410 for performing step 1310 of method 1300, a second means 1420 for performing step 1320 of method 1300, a third means 1430 for performing step 1330 of method 1300, a fourth means 1440 for performing step 1340 of method 1300, a fifth means 1450 for performing step 1350 of method 1300, a sixth means 1460 for performing step 1360 of method 1300, and a seventh means 1470 for performing step 1370 of method 1300.

[0152] Figure 17 A flowchart of a method 1500 for monitoring network resource isolation in a CN domain of a network slice, according to some embodiments, is shown. Method 1500 can be used, for example, in... Figure 3 The NFVO isolation monitoring function 217, as shown in the NFV-MANO 200, is executed at the network management unit.

[0153] refer to Figure 17 Method 1500 may include step 1510 of collecting isolation monitoring data related to virtual resources of the CN NSS. The NFV-MANO 200 may collect the isolation monitoring data via NFVO 210, VNFM 230, and VIM 240. The NFV-MANO 200 may collect the isolation monitoring data periodically during network slicing operation or in response to requests for isolation monitoring data from higher layers, such as the CN isolation monitoring function 134 at the NSS layer. In step 1520, the NFV-MANO 200 may preprocess the collected isolation monitoring data with reference to isolation policies maintained at the NFVO isolation capability repository 216 and the VNF isolation capability repository 231. If the collected isolation monitoring data is not relevant to the CN NSS isolation policy, the NFV-MANO 200 may ignore the data. Then, in step 1530, the NFV-MANO 200 may send the isolation monitoring data to higher-layer isolation monitoring functions, such as the CN isolation monitoring function 134 at the NSS layer.

[0154] Figure 18 A block diagram of a device 1600 according to some example embodiments is shown. Device 1600 may be implemented, for example, in the NFVO isolation monitoring function 217 of the NFV-MANO200 to perform... Figure 17 Method 1500 is shown. (See reference.) Figure 18The device 1600 can comprise a first means (or module or unit) 1610 for performing step 1510 of the method 1500, a second means 1620 for performing step 1520 of the method 500, and a third means 1630 for performing step 1530 of the method 1500.

[0155] Reference has been made to Figures 7-18 The methods 500, 700, 900, 1100, 1300, 1500 and the devices 600, 800, 1000, 1200, 1400, 1600 have been briefly discussed. Details of the methods and apparatuses can also be referred to the above references Figures 1-6 to the network management functions and procedures discussed above.

[0156] Figure 19 A block diagram of a network management unit 1700 according to some example embodiments is shown. The network management unit 1700 can be implemented as any of the above network management functions to perform operations and / or methods related to applying and monitoring fine-grained isolation policies in the CN domain of a network slice. In some embodiments, two or more network management functions can be implemented together as the network management unit 1700. For example, the NS isolation management function 122 and the NS isolation monitoring function 124, or the CN isolation control function 132 and the CN isolation monitoring function 134 can be implemented together as the network management unit 1700.

[0157] Reference is made to Figure 19 The network management unit 1700 can comprise one or more processors 1710, one or more memories 1720 and one or more network interfaces 1730 interconnected together by one or more buses 1740. The one or more buses 1740 can be address, data, or control buses and can comprise any interconnection mechanism, such as a series of lines on a motherboard or integrated circuit, fiber optics, optical devices or other like means, etc. The one or more network interfaces 1730 are provided to support wired and / or wireless communications with other network functions, units, elements or nodes. In some embodiments, the one or more network interfaces 1730 can implement, for example, an NG interface or an Xn interface. The one or more memories 1720 can include computer program code 1722. The one or more memories 1720 and the computer program code 1722 can be configured to, with the one or more processors 1710, cause the network management unit 1700 to perform operations and / or methods as described above.

[0158] The one or more processors 1710 can be of any suitable type appropriate for the local technology network and can include general purpose processors, special purpose processors, microprocessors, digital signal processors (DSPs), one or more of a plurality of core processor architectures based on a processor, and one or more of specialized processors developed on the basis of field programmable gate arrays (FPGA) and application specific integrated circuits (ASIC). The one or more processors 1710 can be configured to control the other elements of the network management unit and operate in cooperation with them to implement the processes described above.

[0159] The one or more memories 1720 can include at least one storage medium of various forms, such as volatile memory and / or non-volatile storage. Volatile memory can include, but is not limited to, for example, random access memory (RAM) or cache. Non-volatile storage can include, but is not limited to, for example, read only memory (ROM), hard disks, flash memory, etc. Furthermore, the one or more memories 1220 can include, but are not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any combination of the above.

[0160] It can be understood that the blocks shown in the figures can be implemented in various ways including software, hardware, firmware, or any combination thereof. In some embodiments, one or more blocks can be implemented using software and / or firmware, such as machine executable instructions stored in a storage medium. In addition to or instead of machine executable instructions, some or all of the blocks in the figures can be implemented at least in part by one or more hardware logic components. For example, and without limitation, illustrative types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system on a chip (SOCs), complex programmable logic devices (CPLDs), etc.

[0161] Some example embodiments also provide computer program code or instructions, which, when executed by one or more processors, can cause a device or apparatus to perform the procedures described above. The computer program code to carry out the procedures of the example embodiments can be written in any combination of one or more programming languages. The computer program code can be provided to one or more processors or controllers of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code can be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a remote machine and partially on a remote machine, or entirely on a remote machine or server.

[0162] Some example embodiments also provide a computer program product, embodied in a computer readable medium, comprising computer program code or instructions. The computer readable medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium will include one or more of an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0163] Moreover, while operations have been described in a particular order, this should not be understood as requiring that such operations be performed in the particular order described, or in sequential order, or that all described operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing can be advantageous. Likewise, while a number of specific implementation details have been included for the purpose of providing a thorough description of certain embodiments, these details are not intended to limit the scope of the disclosure, but rather are included as exemplary features. Certain features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination. Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example implementations of the claims.

[0164] While the subject matter has been described above in terms of specific embodiments, it is not intended that the subject matter be limited to the specific embodiments described. Rather, it is believed that the subject matter is best described in terms of a set of unique features, described above and throughout this detailed description with reference to the drawings, with the realization that many embodiments can be made and equivalences can be substituted. Thus, although the subject matter has been described in detail with respect to particular embodiments, it will be apparent that modifications and variations of these embodiments can be effected, and it is, therefore, contemplated that the application can be practiced otherwise than specifically described.

Claims

1. A method for isolating network slices (NS) in a core network (CN) domain, comprising: Receive the slice isolation policy for the Network Slice Subnet (NSS) in the CN domain; Based on the slice isolation strategy, an NSS isolation strategy is established for the CN NSS, and the NSS isolation strategy includes at least one of a network resource isolation strategy and an application-level isolation strategy. In the case where the NSS isolation policy includes the network resource isolation policy: Map the network resource isolation strategy to a network resource allocation strategy that includes the isolation requirements of virtual and / or physical resources of network services; as well as Send the network resource allocation policy related to the physical resource to the Network Function Management function (NFMF) and / or send the network resource allocation policy related to the virtual resource to the Network Function Virtualization Management and Orchestration (NFV-MANO) function for the instantiation of the network service; as well as In the case where the NSS isolation policy includes the application-level isolation policy: Map the application-level isolation policy to an application-level policy that includes isolation-related requirements for configuring network functions; as well as The application-level policy is sent to the NFMF to configure one or more network functions, wherein the application-level isolation policy includes one or more of control plane isolation, data plane isolation, management plane isolation, and subscriber data isolation.

2. The method of claim 1, further comprising: Receive information for the network service instance of the CN NSS from the NFV-MANO; as well as Maintain the mapping between the NSS isolation policy and the network service instance used for the CN NSS.

3. The method of claim 1, further comprising: When the CN NSS shares the NSS isolation policy with other network slices or NSS, check whether the NSS isolation policy used for the CN NSS conflicts with other network slices or NSS. as well as Trigger a reconfiguration and / or reordering of the CN NSS to eliminate the conflict.

4. The method of claim 1, wherein, The network resource isolation strategy includes one or more of physical isolation and logical isolation. The physical isolation includes one or more of the following: Private Physical Network Function (PNF) isolation, Private Physical Network Link isolation, Geographic Location isolation, Computational Isolation, Memory Isolation, Storage Isolation, and PNF-based Security Isolation. The logical isolation includes one or more of the following: Virtual Network Function (VNF) isolation, Virtual Link isolation, Virtualization Technology isolation, Virtual Computing isolation, Virtual Memory isolation, Virtual Storage isolation, Geographical Location Isolation of Hardware Virtualized to Provide Virtual Resources, and VNF-based Security Isolation.

5. A network management unit, comprising: At least one processor; as well as At least one memory including computer program code, said at least one memory and said computer program code being configured to utilize said at least one processor to cause the network management unit to: Receive the slice isolation policy for Network Slice Subnets (NSS) in the CN domain; Based on the slice isolation strategy, an NSS isolation strategy is established for the CN NSS, and the NSS isolation strategy includes at least one of a network resource isolation strategy and an application-level isolation strategy. In the case where the NSS isolation policy includes the network resource isolation policy: Map the network resource isolation strategy to a network resource allocation strategy that includes isolation-related requirements for virtual and / or physical resources used for network services; as well as Send the network resource allocation policy related to the physical resource to the Network Function Management function (NFMF) and / or send the network resource allocation policy related to the virtual resource to the Network Function Virtualization Management and Orchestration (NFV-MANO) function for the instantiation of the network service; as well as In the case where the NSS isolation policy includes the application-level isolation policy: Map the application-level isolation policy to an application-level policy that includes isolation-related requirements for configuring network functions; as well as The application-level policy is sent to the NFMF to configure one or more network functions, wherein the application-level isolation policy includes one or more of control plane isolation, data plane isolation, management plane isolation, and subscriber data isolation.

6. The network management unit as described in claim 5, wherein, The at least one memory and the computer program code are also configured to utilize the at least one processor to enable the network management unit: Receive information for the network service instance of the CN NSS from the NFV-MANO; as well as Maintain the mapping between the NSS isolation policy and the network service instance used for the CN NSS.

7. The network management unit as described in claim 5, wherein, The at least one memory and the computer program code are also configured to utilize the at least one processor to enable the network management unit: When the CN NSS shares the NSS isolation policy with other network slices or NSS, check whether the NSS isolation policy used for the CN NSS conflicts with other network slices or NSS; as well as Trigger a reconfiguration and / or rearrangement of the CN NSS to eliminate the conflict.

8. A computer-readable medium having instructions stored thereon, which, when executed by at least one processor of a network management unit, cause the network management unit to perform the method of any one of claims 1-4.

Citation Information

Patent Citations

  • Method, device and system for managing network slices

    CN108023749A

  • Network deployment information determination method and equipment

    CN109560955A

  • Network slice deployment method and device

    CN110034944A

  • Network slicing method and network slicing device for 5G core network

    CN110401946A