Allocation of network slice resources
By receiving requests for network slicing allocation resources, obtaining security requirements, determining a security service list, and assigning network slicing instances that meet security requirements, the security and reliability challenges in network slicing deployment are solved, and network slicing allocation that meets different consumer security requirements are achieved.
Patent Information
- Application Number
- CN202080097942.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-03-04
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2040-03-04
AI Technical Summary
In the process of achieving comprehensive end-to-end network slicing deployment, there are challenges such as network slicing security, reliability, scalability and life cycle management, especially in terms of network slicing security, especially the security of network slicing orchestration has attracted attention.
The first device receives a request for allocating resources of the network slice from the second device, obtains the security requirements of the network slice, determines a security service list, and allocates a network slice instance that meets the security requirements.
Different security requirements of different consumers can be met, which improves the security and reliability of network slicing and ensures that the security requirements of network slicing instances are met.
Smart Images

Figure CN115211159B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate generally to communication technology, and more specifically to methods, devices, and computer-readable media for allocating resources for network slicing. Background Art
[0002] With the development of mobile communication technology, people's lives are becoming more and more abundant. In the future, mobile communications will continue to develop, touching industries such as automobiles, manufacturing, logistics, energy, and fields such as finance and medical care that have not yet fully tapped the potential of mobile services. However, the various applications mentioned above have different requirements. Some applications may require ultra-reliable communication, while other applications may require ultra-high bandwidth communication or extremely low latency. Therefore, the "network slicing" technology is introduced to provide different combinations of capabilities while meeting all these different requirements. Summary of the invention
[0003] In general, embodiments of the present disclosure relate to a method and corresponding device for allocating network slices.
[0004] In a first aspect, a first device is provided. The first device includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, together with the at least one processor, cause the first device to: receive a request for allocation resources of a network slice from a second device. The first device is also caused to obtain security requirements of the network slice from the request. The first device is also caused to determine a security service list based on the security requirements. The first device is also caused to allocate a network slice instance that at least meets the security requirements indicated by the received request. The first device is also caused to transmit an indication of the allocated network slice instance to the second device.
[0005] In a second aspect, a second device is provided. The second device includes at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to, together with the at least one processor, cause the second device to: generate a request for allocation resources of a network slice, the request indicating at least a security requirement. The second device is also caused to transmit the request to the first device. The second device is also caused to receive an indication of an allocated network slice instance from the first device, the allocated network slice instance satisfying at least the security requirement.
[0006] In a third aspect, a method is provided. The method includes receiving, at a first device, a request for allocated resources for a network slice from a second device. The method also includes obtaining security requirements for the network slice from the request. The method also includes determining a security service list based on the security requirements. The method also includes allocating a network slice instance that supports the security service list. The method also includes transmitting an indication of the allocated network slice instance to the second device.
[0007] In a fourth aspect, a method is provided. The method includes generating a request for allocated resources for a network slice, the request indicating at least a security requirement. The method also includes transmitting the request to a first device. The method also includes receiving an indication of an allocated network slice instance from the first device, the allocated network slice instance satisfying at least the security requirement.
[0008] In a fifth aspect, an apparatus is provided. The apparatus includes a component for receiving, at a first device, a request for allocation resources of a network slice from a second device; a component for obtaining security requirements of the network slice from the request; a component for determining a security service list based on the security requirements; a component for allocating a network slice instance that supports the security service list; and a component for transmitting an indication of the allocated network slice instance to the second device.
[0009] In a sixth aspect, an apparatus is provided. The apparatus comprises a component for generating a request for allocation of resources for a network slice, the request indicating at least a security requirement; a component for transmitting the request to a first device; and a component for receiving an indication of an allocated network slice instance from the first device, the allocated network slice instance satisfying at least the security requirement.
[0010] In a seventh aspect, a computer-readable medium is provided, the computer-readable medium comprising program instructions for causing an apparatus to at least execute the method according to the third aspect or the fourth aspect above.
[0011] In an eighth aspect, a computer program product is provided, which is stored on a computer-readable medium and includes machine-executable instructions, wherein the machine-executable instructions, when executed, cause the machine to perform the method according to the third aspect or the fourth aspect above.
[0012] It should be understood that the invention summary is not intended to determine the key or essential features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Some example embodiments will now be described with reference to the accompanying drawings, in which:
[0014] Figure 1 A schematic diagram showing a communication system according to some example embodiments of the present disclosure;
[0015] Figure 2 A block diagram of a network slicing system according to some example embodiments of the present disclosure is shown;
[0016] Figure 3A flowchart showing a method according to some example embodiments of the present disclosure is shown;
[0017] Figure 4 A schematic diagram showing interactions between devices according to some example embodiments of the present disclosure;
[0018] Figure 5 A schematic diagram showing interactions between devices according to some example embodiments of the present disclosure;
[0019] Figure 6 A flowchart showing a method according to some example embodiments of the present disclosure is shown;
[0020] Figure 7 shows a simplified block diagram of an apparatus suitable for implementing an example embodiment of the present disclosure; and
[0021] Figure 8 A block diagram of an example computer-readable medium is shown according to some example embodiments of the present disclosure.
[0022] Throughout the drawings, the same or similar reference numerals refer to the same or similar elements. DETAILED DESCRIPTION
[0023] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that the description of the example embodiments is only for the purpose of illustrating and helping those skilled in the art to understand and implement the present disclosure, and does not represent any limitation on the scope of the present disclosure. The disclosure described herein can be implemented in various other ways except for the way described below.
[0024] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.
[0025] References in this disclosure to "one embodiment," "an embodiment," "an example embodiment," etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes the particular feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in conjunction with an example embodiment, it is considered to be within the knowledge of those skilled in the art to affect such feature, structure, or characteristic in conjunction with other embodiments (whether or not explicitly described).
[0026] It should be understood that although the terms "first" and "second" etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another element. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element without departing from the scope of the exemplary embodiments. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.
[0027] The terms used herein are for the purpose of describing specific embodiments only and are not intended to limit the example embodiments. As used herein, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises", "comprising", "has", "having", "includes", and / or "including" when used herein specify the presence of the features, elements, and / or components, etc., but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.
[0028] As used in this application, the term "circuitry" may refer to one, more, or all of the following:
[0029] (a) a pure hardware circuit implementation (such as an implementation using only analog and / or digital circuitry), and
[0030] (b) a combination of hardware circuitry and software such as (where applicable):
[0031] (i) a combination of analog and / or digital hardware circuits and software / firmware, and
[0032] (ii) any portion of hardware processor(s) (including digital signal processor(s)), software and memory(s) with software that work together to cause a device (such as a mobile phone or server) to perform various functions, and
[0033] (c) Hardware circuit(s) and / or processor(s), such as microprocessor(s) or portion(s) of microprocessor(s), which requires software (e.g., firmware)
[0034] The software can be saved when no operation is needed.
[0035] This definition of circuitry applies to all uses of the term in this application, including in any claims. As another example, as used in this application, the term circuitry also covers an implementation of only a hardware circuit or processor (or multiple processors) or a portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. For example, if applicable to a particular claim element, the term circuitry also covers a baseband integrated circuit or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or network device.
[0036] As used herein, the term "communication network" refers to a network that follows any suitable communication standard, such as long term evolution (LTE), advanced LTE (LTE-A), wideband code division multiple access (WCDMA), high speed packet access (HSPA), narrowband Internet of Things (NB-IoT), new radio (NR), etc. In addition, the communication between the terminal equipment and the network equipment in the communication network can be performed according to the communication protocol of any suitable generation, including but not limited to the first generation (1G), second generation (2G), 2.5G, 2.55G, third generation (3G), fourth generation (4G), 4.5G, future fifth generation (5G) communication protocol, and / or any other protocol currently known or developed in the future. The embodiments of the present disclosure can be applied to various communication systems. In view of the rapid development of communication, there will certainly be communication technologies and systems that can embody future types of the present disclosure. It should not be considered that the scope of the present disclosure is limited to the above-mentioned system.
[0037] As used herein, the term "network device" refers to a node in a communication network via which a terminal device accesses the network and receives services from it. A network device may refer to a base station (BS) or an access point (AP), such as a NodeB (NodeB or NB), an evolved NodeB (eNodeB or eNB), a NR NB (also known as a gNB), a remote radio unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, an integrated access and backhaul (IAB) node, a low power node (such as a femto, a pico), etc., depending on the terminology and technology applied.
[0038] The term "terminal device" refers to any terminal device capable of wireless communication. As an example and not limitation, the terminal device may also be referred to as a communication device, a user equipment (UE), a subscriber station (SS), a portable subscriber station, a mobile station (MS) or an access terminal (AT). The terminal device may include, but is not limited to, a mobile phone, a cellular phone, a smart phone, a voice over IP (VoIP) phone, a wireless local loop phone, a tablet computer, a wearable terminal device, a personal digital assistant (PDA), a portable computer, a desktop computer, an image acquisition terminal device such as a digital camera, a game terminal device, a music storage and playback device, a vehicle-mounted wireless terminal device, a wireless endpoint, a mobile station, a laptop embedded device (LEE), a laptop mounted device (LME), a USB dongle, a smart device, a wireless client device (CPE), an Internet of Things (IoT) device, a watch or other wearable device, a head mounted display (HMD), a vehicle, a drone, medical equipment and applications (e.g., remote surgery), industrial equipment and applications (e.g., robots and / or other wireless devices operating in industrial and / or automated processing chain environments), consumer electronic devices, equipment commercial operations and / or industrial wireless networks, etc. In the following description, the terms "terminal device", "communication device", "terminal", "user equipment" and "UE" may be used interchangeably.
[0039] The term "network slicing" as used herein refers to the technology that allows multiple logical networks to be created on top of a common shared physical infrastructure. The term "network slice" as used herein refers to an independent end-to-end logical network running on a shared physical infrastructure that is capable of providing a negotiated quality of service. A network slice is self-contained in terms of operations and traffic flows and can have its own network architecture, engineering mechanisms, and network provisioning. Virtualized network resources are typically architected, partitioned, and organized to enable flexible support for different use case implementations. The term "network slice instance" as used herein refers to an instance of a network slice that is created based on a network slice blueprint / template / resource module. The term "network slice orchestration" as used herein refers to automation and customization capabilities that are used to improve service performance and customer satisfaction. Orchestration can automate service creation and delivery. The term "network slice subnet" as used herein refers to a logical network consisting of a set of hosted network functions and the required resources (e.g., compute, storage, and network resources). The term "network slice subnet instance" as used herein refers to an instance of a network slice subnet that is created based on a network slice subnet blueprint / template / resource module.
[0040] As mentioned above, "network slicing" technology has been introduced to provide different combinations of capabilities to meet all these different requirements at the same time. Through network slicing, various types of users / customers can enjoy connections and data processing tailored to their specific requirements (e.g., data speed, quality, latency, reliability, security, and services) that comply with the service level agreement (SLA) agreed with the communication service provider. However, there are some challenges in achieving comprehensive end-to-end network slicing deployment for consumers, enterprises, and government departments, such as end-to-end accurate slicing, network slicing reliability, network slicing scalability, and network slicing lifecycle management. One of the most important challenges is network slicing security, which is beginning to receive attention from academia and industry.
[0041] Network slicing security includes several aspects, such as network slice management security, network slice orchestration security, and network slice access security. The security of network slice orchestration is very important, but has received little attention in the industry so far.
[0042] In some conventional technologies, the management security of network slices has been defined, such as authentication, authorization, integrity protection, and confidentiality protection of the interface between the management service producer and the management service consumer. In addition, network slice specific authentication and authorization, data confidentiality and integrity, user identity privacy, and inter-slice security isolation are also proposed. Some other conventional technologies have defined the security of network slice management exposure interfaces and the integrity protection of the network slice subnet template (NSST). However, there is little research on the security of network slice orchestration.
[0043] According to an embodiment of the present disclosure, a first device receives a request for allocation resources of a network slice from a second device. The first device allocates a network slice instance that meets security requirements based on the request. In this way, different security requirements of different consumers can be met.
[0044] Figure 1 A schematic diagram of a communication system in which embodiments of the present disclosure may be implemented is shown. The communication system 100 includes a first device 110 and a second device 120. The communication system 100 as part of a communication network includes a device 130-1, a device 130-2, ..., a device 130-N (which may be collectively referred to as "(multiple) third devices 130"). One or more devices are associated with a cell and are covered by the cell. It should be understood that Figure 1 The number of devices and cells shown is given for illustrative purposes and does not imply any limitation. The communication system 100 may include any suitable number of devices and cells. In the communication system 100, the first device 110, the second device 120, and the third device 130 may transmit data and control information to each other. Figure 1The number of devices shown is given for illustrative purposes and does not imply any limitation. The second device 120 and the first device 110 are interchangeable. The first device 110 may be a network device. Alternatively, the first device 110 may be a core network device. The second device 120 may communicate with the first device 110 to create a network slice instance. Thereafter, the third device 130 may communicate with each other through the network slice instance. The third device 130 may be a terminal device. Alternatively, the third device 130 may include a network device, for example, the third devices 130-3 and 130-4 may be network devices. The number of third devices is just an example. The third device 130 may be able to access the network slice instance. The first device 110 will manage and monitor the status of the network slice instance through the third device 130-3 and / or 130-4.
[0045] The communication in the communication environment 100 can be implemented according to any (multiple) appropriate communication protocols, including but not limited to cellular communication protocols of the first generation (1G), second generation (2G), third generation (3G), fourth generation (4G) and fifth generation (5G), wireless local area network communication protocols such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocol currently known or developed in the future. In addition, the communication can utilize any appropriate wireless communication technology, including but not limited to: code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), frequency division duplexer (FDD), time division duplexer (TDD), multiple input multiple output (MIMO), orthogonal frequency division multiple access (OFDMA), and / or any other technology currently known or to be developed in the future.
[0046] Hereinafter, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. Figure 2 FIG. 2 is a block diagram of a network slicing system 200 according to some example embodiments of the present disclosure. The network slicing system 200 is only an example and not a limitation. The network slicing system 200 may also include Figure 2 Other modules not shown in the figure. The network slicing system 200 can be implemented at any suitable device, such as the first device 110.
[0047] like Figure 2 As shown, the network slicing system 200 may include a network slice (NS) consumption portal 205, which may receive a request for allocated resources of a network slice from a consumer (e.g., a healthcare provider). The network slicing system 300 may include a NS management and orchestration portion 210. The NS management module 2110 may support the operation of a network slice instance. For example, the operation may be one or more of activation, supervision, performance reporting, resource capacity planning, and modification.
[0048] The NS data collection module 2120 can be configured to collect network data (e.g., data related to services, network slices, network slice subnets and / or network functions) to support improving network performance and efficiency to adapt to and support the diversity of services and requirements.
[0049] In some embodiments, the NS management and orchestration part 210 may also include a NS data analysis module 2130, which is configured to utilize the collected network data to perform analysis in order to assist and supplement management services to obtain optimal network performance and service assurance. The NS instance inventory module 2160 may be configured to store information about available network slice instances.
[0050] like Figure 2 As shown, the network slicing system 200 includes a NS orchestration module 2140 configured to request allocated resources for a network slice. In addition, the network slice module describing the static parameters and functional components of the network slice is stored in the NS resource module 2150. In other embodiments, there are other modules in the network slicing system 200, such as a NS security policy module 2170, a NS security data collection module 2180, and a NS security data analysis module 2190. For example, the NS security policy module 2170 can be configured to support reflecting the security requirements of the requested network slice service to the network slice security policy. In some example embodiments, the NS security data collection module 2180 can be configured to collect security policy implementation status about network data (e.g., services, network slices, network slice subnets, and / or network function-related data) to support checking whether the security requirements of the requested network slice service are met. The NS security data analysis module 2190 can be configured to perform analysis using the collected network data about the security policy implementation status to obtain the best network slice security guarantee. The details of the above modules will be described later with reference to the accompanying drawings.
[0051] In some embodiments, a network slice may include multiple NS subnets (NSSs), for example, NSS 220-1, NSS 220-2, or NSS 220-3. For an NSS, there are some related modules. Figure 2As shown, NSS (e.g., NSS 220-1) may include one or more of the following: NSS management module 2210, NSS data collection module 2220, NSS data analysis module 2230, NSS orchestration module 2240, NSS resource module 2250, NSS instance inventory module 2260, NSS security control module 2270, NSS security data collection module 2280, and NSS security data analysis module 2290. NS subnets may be divided based on different domains, such as geographic regions. Alternatively, NS subnets may be divided based on different functions. For example, one or more NS subnets may have certain security features.
[0052] The functions of the above modules in NSS are similar to those in network slicing and will be described later. For example, the NSS security control module 2270 can be configured to support setting the network slice security policy as a network slice subnet security control. In some embodiments, the NSS security data collection module 2280 can be configured to collect security policy implementation status about network data (e.g., network slices, network slice subnets, and / or network function related data) to support checking whether the security requirements of the requested network slice subnet are met. In addition, the NSS security data analysis module 2290 can be configured to use the collected network data about the security policy implementation status to perform analysis to obtain the best network slice subnet security guarantee.
[0053] The network slicing system 200 may also include a network function virtualization management and orchestration (NFV-MANO) module 230, which is configured to manage the network function virtualization infrastructure (NFVI) and orchestrate the resource allocation required for network services and virtual network functions (VNFs). The NFV orchestrator (NFVO) module 240 in the network slicing system 200 may be responsible for the orchestration of NFVI resources across multiple virtual infrastructure managers (VIMs) and the lifecycle management of network services. In some embodiments, the NFVO module may include a network service catalog module 2410, a VNF catalog module 2420, a VFV instance inventory 2430, and a NFVI resource module 2440.
[0054] In some example embodiments, the network slicing system 200 may include a VNF manager (VNFM) configured to be responsible for the lifecycle management of VNF instances. A virtualized infrastructure manager (VIM) module 270 may be configured to be responsible for controlling and managing NFVI computing, storage, and network resources. An SDN control module including a data forwarding strategy may be included in the VIM.
[0055] like Figure 2As shown, the NFV-MANO module 230 may also include a NFV security manager module 250 configured to manage the security of network services throughout their life cycle. In addition, the security service catalog module 2510 in the NFV security manager module 250 may be a new logical function with the following capabilities: 1) Store all onboard security services; 2) Support the creation and management of security service resource models; 3) Support the creation of network slice subnet instances (i.e., NSS_security). The NFV security manager module 250 may also include a virtual security function (VSN) catalog module 2520, which is a specific type of VNF catalog. The NFV security manager module 250 may also include a VSF instance 2530, which is a specific type of VNF instance. The VSF used in this article may refer to a special type of VNF with customized security functions (e.g., firewall, IDS / IPS, virtualization security monitoring function).
[0056] In an example embodiment, the network slicing system 200 may include a NFVI security manager 230 configured to build and manage security in the NFVI to support NFV security manager requests for managing the security of network services in a high layer. The VNF modules 285 in the network slicing system 200 may include VNFs and virtual security functions (VSFs), which are special types of VNFs with customized security functions (e.g., firewalls, IDS / IPS, virtualized security monitoring functions). The NFVI-based security function module 290 may be a security function provided by the NFV infrastructure. It includes virtualized security devices or software security features (e.g., hypervisor-based firewalls) and hardware-based security devices / modules / features (e.g., hardware security modules, cryptographic accelerators, or trusted platform modules). The physical network function (PNF) module 295 in the network slicing system 200 may include one or more PNFs and one or more physical security functions (PSFs), which are security functions that are conventionally implemented in the physical part of the hybrid network.
[0057] Reference now Figure 3 , Figure 3 The signaling flow 300 for allocating network slices according to some example embodiments of the present disclosure is shown. For ease of discussion, reference will be made to Figure 2 The process 300 is described. The signaling flow 300 may involve the first device 110 and the second device 120. It should be noted that Figure 3 The signaling flow shown is only an example.
[0058] Reference now Figure 3 , Figure 3 FIG. 3 is a flowchart showing a method 300 of allocating network slices according to some example embodiments of the present disclosure. For the purpose of discussion, reference will be made to Figure 2 The method 300 is described. The method 300 may be implemented at any suitable device. For example, the method may be implemented at the first device 110.
[0059] In box 310, the first device 110 receives a request for allocated resources for a network slice from the second device 120. The request can be transmitted to the first device 110 via the NS consumption portal 205. The request indicates one or more characteristics of the network slice. For example, the request indicates the security requirements of the network slice. In some embodiments, the request may indicate the network slice type. Alternatively or in addition, the request may indicate the bandwidth of the network slice. These characteristics may include the priority of the network slice. In some example embodiments, the latency requirements of the network slice may be indicated in the request. The request may also indicate the throughput of the network slice and / or the maximum number of terminal devices accessing the network slice.
[0060] In some embodiments, the first device 110 may perform authentication of the second device 120 based on credentials or a pre-shared key. Alternatively or additionally, the second device 120 may be authorized by the first device 110 based on a white / black list or an access control list (ACL).
[0061] In block 320, the first device 110 obtains security requirements of the network slice from the request. In block 330, the first device 110 determines a security service list based on the security requirements.
[0062] At block 340, the first device 110 allocates a network slice instance that supports the list of security services. The network slice instance satisfies at least the security requirements specified in the request. For example, if the request indicates that isolated hardware is required, the network slice may be allocated with isolated hardware. In this way, the security requirements of the requested network slice may be met.
[0063] In some example embodiments, the first device 110 may map a security service list to a plurality of network slice resource modules and obtain information of available network slice instances. The first device 110 may obtain a security status of an available network slice instance and determine whether an existing network slice instance meets the security requirements. If the existing network slice instance meets the security requirements, the first device 110 may determine the existing network slice instance as an allocated resource for the requested network slice subnet. If the existing network slice instance does not meet the profile of the network slice subnet, the first device 110 may create a network slice instance based at least in part on the security requirements.
[0064] In other example embodiments, the first device 110 may map the security service list to multiple network slice subnet resource modules and obtain information of available network slice subnet instances. The first device 110 may obtain the security status of the available network slice subnet instances and determine whether the existing network slice subnet instances meet the security requirements. If the existing network slice subnet instances meet the security requirements, the first device 110 may determine the existing network slice subnet instances as allocated resources for the requested network slice subnet. If the existing network slice subnet instances do not meet the profile of the network slice subnet, the first device 110 may create a network slice subnet instance based at least in part on the security requirements.
[0065] Figure 4 and Figure 5 Schematic diagrams of interactions 400 and 500 for allocating network slice instances according to some example embodiments of the present disclosure are shown, respectively. In particular, Figure 4 shows the interaction of allocating network slice instances at the NS level, Figure 5 The interaction of allocating network slice subnet instances at the NSS level is shown.
[0066] like Figure 4 As shown, the NS orchestration module 2140 can obtain 4005 security requirements from the received request. The NS orchestration module 2140 can determine 4010 a list of security service types based on the security requirements. For example, the NS orchestration module 2140 can determine the isolation of data transmission based on the security requirements. Alternatively, the list of security service types can include virus detection and data cleaning. In some example embodiments, the NS orchestration module 2140 can determine that management data needs to be tamper-proof. Confidentiality protection of data during transmission can be included in the list of security service types. In other embodiments, the list of security service types can further perform integrity protection on data during transmission. The list of security service types can also include one or more of the following: hardware isolation, software isolation, anti-DDoS attack, anti-virus and anti-malware. It should be noted that the embodiments of the present disclosure are not limited to this.
[0067] The NS orchestration module 2140 may access 4015 the NS resource module 2150 to obtain the security status of the network slice instance. As described above, the NS resource module 2150 may store network slice modules that describe static parameters and functional components of the network slice. The NS orchestration module 2140 may map 4020 the received request with a list of security service types to an appropriate NS resource module. For example, the security profile of the appropriate NS resource module may meet the security requirements indicated in the request. The security profile of the appropriate NS resource module may include data encryption. In other example embodiments, data integrity verification may be included in the security profile. The profile may also include data filtering and / or data cleansing. Alternatively or in addition, the appropriate NS resource module may be able to support the required services indicated in the request.
[0068] The NS orchestration module 2140 may access 4025 the NS instance inventory module 2160 to obtain information about available network slice instances. The NS orchestration module 2140 may determine 4030 whether an existing network slice instance satisfies the request. In some example embodiments, the NS orchestration module 2140 may check whether an available network slice instance can support the required service based on the information obtained from the NS instance inventory module 2160. The NS orchestration module 2140 may also check whether an available network slice instance can meet the security requirements in the request based on the information obtained from the NS instance inventory module 2160. If there is an existing network slice instance that meets the security requirements, the NS orchestration module 2140 may allocate 4035 the existing network slice instance to the allocation of the requested network slice. If there is no existing network slice instance that meets the security requirements, the NS orchestration module 2140 may create 4040 a new network slice instance. The NS orchestration module 2140 may determine a plurality of subnets, for example, subnets 220-1, 220-2, and 220-3, for creating a network slice instance. The NS orchestration module 2140 can create a network slice instance by linking multiple NS subnets. The NS orchestration module 2140 can transmit an additional request to the NSS orchestration module 2240 to allocate resources to multiple NS subnets. Figure 4 Not shown. Figure 5 The interactions for creating a network slice subnet instance at the NSS level are shown.
[0069] If the NSS orchestration module 2240 receives an additional request from the NS orchestration module 2140, the NSS orchestration module 2240 may authenticate and authorize the NS orchestration module 2140. The NSS orchestration module 2240 may access 5015 the NSS resource module 2250. As described above, the NSS resource module 2250 may store a network slice subnet module that describes static parameters and functional components of the network slice subnet. The NSS resource module 2250 may obtain the security status of the network slice subnet instance. The NSS orchestration module 2240 may receive a list of security service types received.
[0070] The request is mapped 5020 to an appropriate NSS resource module. For example, an appropriate NSS resource module
[0071] The security profile of the block may satisfy the security requirements indicated in the other request. The security profile of the appropriate NSS resource module may include data encryption. In other example embodiments, data integrity verification may be included in the security profile. The profile may also include data filtering and / or data cleaning. Alternatively or additionally, the appropriate NSS resource module may be able to support the required services indicated in the request.
[0072] The NSS orchestration module 2240 may access 5025 the NSS instance inventory module 2260 to obtain information about available network slice subnet instances. The NSS orchestration module 2240 may determine 5030 whether an existing network slice subnet instance satisfies the request. In some example embodiments, the NSS orchestration module 2240 may check whether an available network slice subnet instance can support the required service based on the information obtained from the NSS instance inventory module 2260. The NSS orchestration module 2240 may also check whether an available network slice subnet instance can meet the security requirements in another request based on the information obtained from the NSS instance inventory module 2260. If there is an existing network slice subnet instance that meets the security requirements, the NSS orchestration module 2240 may allocate 5035 the existing network slice subnet instance to the allocated resources of the requested network slice subnet. The NSS orchestration module 2240 may provide the security status of the network slice subnet instance to the NS orchestration module 2140.
[0073] If there is no existing network slice subnet instance that meets the security requirements, the NSS orchestration module 2240 may create 5040 a new network slice subnet instance. The NSS orchestration module 2240 may transmit 5045 another request for allocation resources for the network service to the NFV-MANO 230. The NFV-MANO 230 may perform 5050 authentication of the other request based on the credential and authorization of the other request based on the ACL or white / black list.
[0074] After authentication and authorization, NFV-MANO 230 may allocate 5055 the requested allocated resources for the network slice subnet to one or more existing network service instances that meet the security requirements. Alternatively, NFV-MANO 230 may create a new network service instance for the requested allocation of the network slice subnet. NFV-MANO 230 may transmit 5060 a confirmation of the network service to NSS orchestration module 2240. In some embodiments, NSS orchestration module 2240 may confirm the allocation of the network slice subnet instance to NS orchestration module 2140.
[0075] Reference again Figure 3 At block 350, first device 110 transmits an indication of the allocation of the network slice instance to second device 120. For example, NS orchestration module 2140 may transmit the indication to second device 120 via NS consumption portal 205. NS orchestration module 2140 may also provide second device 120 with a security status of the network slice instance.
[0076] In some example embodiments, the first device 110 may monitor data on the allocated network slice instance. The first device 110 may determine whether the security requirements of the network slice are met based on the monitored data. The data may refer to a date associated with a network slice instance or a network slice subnet instance. For example, the NS security data collection module 2180 may collect the security policy implementation status of the monitoring data to support checking whether the security requirements of the allocated resources of the requested network slice are met. The NS security data analysis module 2190 may use the collected network data on the security policy implementation status to perform analysis to obtain the best network slice subnet security guarantee. The NS security policy module 2170 may support setting the network slice security policy as a network slice subnet security control. If the security requirements are not met, the first device 110 may update the allocated resources of the network slice. For example, the first device 110 may recreate or reallocate the network slice instance.
[0077] After allocating the network slice instance, the first device 110 may monitor the third device 130-1 through other devices (e.g., devices 130-3 and / or 130-4 as network devices). The first device 110 may also monitor access data from the third device 130-3 and / or 130-4. Abnormal behavior of the third device 130-1 may be detected by the first device 110 based on access data of the third device 130-1 via devices 130-3 and / or 130-4 on the network slice instance.
[0078] Figure 6A flowchart of a method 600 for allocating network slices according to some example embodiments of the present disclosure is shown. The method 600 can be implemented at any suitable device. For example, the method can be implemented at the second device 120.
[0079] At block 610, the second device 120 generates a request for allocation of a network slice. The request indicates one or more characteristics of the network slice. For example, the request indicates security requirements for the network slice. In some embodiments, the request may indicate a network slice type. Alternatively or additionally, the request may indicate a bandwidth for the network slice. These characteristics may include a priority for the network slice. In some example embodiments, a latency requirement for the network slice may be indicated in the request. The request may also indicate a throughput for the network slice and / or a maximum number of terminal devices accessing the network slice.
[0080] At block 620, the second device 120 transmits the request to the first device 110. For example, the request may be transmitted to the first device 110 via the NS consumption portal 205. In some embodiments, the second device 120 may be authenticated by the first device 110 on a credential or pre-shared key. Alternatively or additionally, the second device 120 may be authorized by the first device 110 based on a white / black list or an access control list (ACL).
[0081] At block 630, second device 120 receives an indication of an allocation of a network slice instance for second device 120. For example, the indication may be received via NS consumption portal 205. NS orchestration module 2140 may also provide second device 120 with a security status of the network slice instance.
[0082] In some embodiments, if the security requirements are not met, the second device 120 may receive a further indication of an updated allocated resource for the network slice. Alternatively, the second device 120 may receive another indication of a detection of an abnormal behavior of the third device 130.
[0083] In an embodiment, an apparatus for executing method 300 (e.g., first device 110) may include corresponding components for executing corresponding steps in method 300. These components may be implemented in any suitable manner. For example, it may be implemented by a circuit system or a software module.
[0084] In some embodiments, the apparatus includes a component for receiving, at a first device, a request for allocated resources for a network slice from a second device; a component for obtaining security requirements for the network slice from the request; a component for determining a security service list based on the security requirements; a component for allocating a network slice instance that supports the security service list; and a component for transmitting an indication of the allocated network slice instance to the second device.
[0085] In some embodiments, the component for allocating a network slice instance includes: a component for mapping a security service list to a network slice resource module; a component for obtaining information about available network slice instances; a component for obtaining the security status of available network slice instances; a component for determining whether an existing network slice instance meets security requirements; a component for determining an existing network slice instance as an allocated resource of a requested network slice based on a determination that an existing network slice instance meets security requirements; or a component for creating a new network slice instance based at least in part on security requirements based on a determination that an existing network slice instance does not meet a profile of the network slice.
[0086] In some embodiments, the components for creating a network slice instance include: a component for allocating multiple network slice subnet instances that meet security requirements and required services; and a component for creating a network slice instance by linking multiple network slice subnet instances.
[0087] In some embodiments, the component for allocating multiple network slice subnet instances includes a component for mapping a security service list to multiple network slice subnet resource modules; a component for obtaining information about available network slice subnet instances; a component for obtaining the security status of available network slice subnet instances; a component for determining whether an existing network slice subnet instance meets security requirements; a component for determining an existing network slice subnet instance as an allocated resource of the requested network slice subnet based on determining that the existing network slice subnet instance meets the security requirements; or a component for creating a network slice subnet instance based at least in part on security requirements based on determining that an existing network slice subnet instance does not meet the profile of the network slice subnet.
[0088] In some embodiments, the device also includes a component for determining whether security requirements of the network slice are met based on the data in response to monitoring the data on the network slice instance; and a component for updating the allocated resources of the network slice based on determining that the security requirements are not met.
[0089] In some embodiments, the apparatus further includes a component for detecting abnormal behavior of a third device by monitoring access data of the third device on the network slice instance.
[0090] In some embodiments, the device includes a component for mapping a security service list to a network slice resource module; a component for obtaining the security status of one or more network slice instances; and a component for allocating network slice instances based on the network slice resource module.
[0091] In some embodiments, the first device is a network device, the second device is another network device, and the third device is a terminal device or another network device.
[0092] In an embodiment, an apparatus for executing method 600 (e.g., second device 120) may include corresponding components for executing corresponding steps in method 600. These components may be implemented in any suitable manner. For example, it may be implemented by a circuit system or a software module.
[0093] In some embodiments, the apparatus includes a component for generating a request for allocated resources for a network slice, the request indicating at least a security requirement; a component for transmitting the request to a first device; and a component for receiving an indication of an allocated network slice instance from the first device, the allocated network slice instance satisfying at least the security requirement.
[0094] In some embodiments, the apparatus further comprises means for receiving a further indication of updated allocated resources for the network slice based on determining that the security requirements are not met.
[0095] In some embodiments, the apparatus further comprises means for receiving, from the first device, another indication of the detection of abnormal behavior of the third device.
[0096] In some embodiments, the first device is a network device, the second device is another network device, and the third device is a terminal device or another network device.
[0097] Figure 7 700 is a simplified block diagram of a device 700 suitable for implementing an embodiment of the present disclosure. The device 700 may be provided to implement a communication device, such as Figure 1 The first device 110 or the second device 120 is shown. As shown in the figure, the device 700 includes one or more processors 710, one or more memories 720 coupled to the processor 710, and one or more communication modules 740 coupled to the processor 710.
[0098] The communication module 740 is used for two-way communication. The communication module 740 has at least one antenna to facilitate communication. The communication interface may represent any interface necessary to communicate with other network elements.
[0099] Processor 710 may be of any type suitable for the local technology network, and may include, as non-limiting examples, one or more of a general purpose computer, a special purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. Device 700 may have multiple processors, such as application specific integrated circuit chips that are time slaved to a clock synchronized with a main processor.
[0100] The memory 720 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 724, electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disk (CD), digital video disk (DVD), and other magnetic storage and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 722 and other volatile memories that do not persist during power outages.
[0101] The computer program 730 includes computer executable instructions that are executed by the associated processor 710. The program 730 may be stored in the ROM 724. The processor 710 may perform any suitable actions and processes by loading the program 730 into the RAM 722.
[0102] The embodiments of the present disclosure may be implemented by a program 720, so that the device 700 may execute the Figure 2 and Figure 6 The embodiments of the present disclosure may also be implemented by hardware, or a combination of software and hardware.
[0103] In some example embodiments, the program 730 may be tangibly embodied in a computer-readable medium, which may be included in the device 700 (such as the memory 720) or other storage devices accessible to the device 700. The device 700 may load the program 730 from the computer-readable medium to the RAM 722 for execution. The computer-readable medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. Figure 8 An example of a computer readable medium 800 in the form of a CD or DVD is shown. The computer readable medium has a program 730 stored thereon.
[0104] It should be understood that future networks may utilize network function virtualization (NFV), which is a network architecture concept that proposes virtualizing network node functions into "building blocks" or entities that can be operationally connected or linked together to provide services. A virtualized network function (VNF) may include one or more virtual machines that use standard or general-purpose types of servers rather than custom hardware to run computer program code. Cloud computing or data storage may also be used. In radio communications, this may mean that node operations are at least partially performed in a central / centralized unit CU (e.g., a server, host, or node) that is operationally coupled to a distributed unit DU (e.g., a radio head / node). Node operations may also be distributed among multiple servers, nodes, or hosts. It should also be understood that the distribution of work between core network operations and base station operations may vary depending on the implementation.
[0105] In one embodiment, the server can generate a virtual network through which the server communicates with the distributed unit. In general, a virtual network can involve the process of combining hardware and software network resources and network functions into a single software-based management entity (virtual network). Such a virtual network can provide a flexible distribution of operations between the server and the radio head / node. In practice, any digital signal processing task can be performed in the CU or DU, and the boundary of the responsibility transfer between the CU and the DU can be selected according to the implementation.
[0106] Thus, in one embodiment, a CU-DU architecture is implemented. In this case, the device 700 may be included in a central unit (e.g., a control unit, an edge cloud server, a server) that is operably coupled (e.g., via a wireless or wired network) to a distributed unit (e.g., a remote radio head / node). That is, the central unit (e.g., an edge cloud server) and the distributed units may be independent devices that communicate with each other via a radio path or via a wired connection. Alternatively, they may be in the same entity that communicates via a wired connection, etc. The edge cloud or edge cloud server may serve multiple distributed units or radio access networks. In one embodiment, at least some of the described processes may be performed by the central unit. In another embodiment, the device 700 may instead be included in a distributed unit, and at least some of the described processes may be performed by the distributed unit.
[0107] In one embodiment, the execution of at least some functions of the device 500 can be shared between two physically separate devices (DU and CU) that form an operational entity. Therefore, the device can be regarded as depicting an operational entity including one or more physically separate devices for performing at least some of the described processes. In one embodiment, such a CU-DU architecture can provide a flexible distribution of operations between the CU and the DU. In practice, any digital signal processing task can be performed in the CU or the DU, and the boundary of the transfer of responsibilities between the CU and the DU can be selected according to the implementation. In one embodiment, the device 500 controls the execution of the process regardless of the location of the device and where the process / function is executed.
[0108] Generally, various embodiments of the present disclosure may be implemented using hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects may be implemented using hardware, while other aspects may be implemented using firmware or software that may be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of the present disclosure are illustrated and described as block diagrams, flow charts, or using some other graphical representations, it should be understood that, as non-limiting examples, the blocks, devices, systems, techniques, or methods described herein may be implemented using hardware, software, firmware, dedicated circuits or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.
[0109] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer executable instructions, such as instructions included in a program module, which are executed in a device on a target real or virtual processor to perform the above referenced Figure 3 and Figure 6 Methods 300 and 400 described herein. Typically, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types. In various embodiments, the functions of program modules can be combined or split between program modules as needed. The machine executable instructions of program modules can be executed in local or distributed devices. In distributed devices, program modules can be located in both local and remote storage media.
[0110] The program code for executing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer or other programmable data processing device so that the program code causes the function / operation specified in the flow chart and / or block diagram to be realized when executed by the processor or controller. The program code can be executed completely on the machine, partially on the machine, as an independent software package, partially on the machine and partially on a remote machine, or completely on a remote machine or server.
[0111] In the context of the present disclosure, computer program codes or related data may be carried by any suitable carrier to enable a device, apparatus or processor to perform various processes and operations as described above. Examples of carriers include signals, computer readable media, etc.
[0112] The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. A more specific example of a computer readable storage medium will include an electrical connection with one or more wires, a portable computer floppy disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0113] In addition, although the operations are described in a particular order, this should not be understood as requiring such operations to be performed in the particular order shown or in order or performing all the operations shown to obtain the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be interpreted as limitations on the scope of the present disclosure, but rather descriptions of features that may be specific to a particular embodiment. Certain features described in the context of a separate embodiment may also be implemented in combination in a single embodiment. On the contrary, the various features described in the context of a single embodiment may also be implemented in multiple embodiments individually or in any suitable sub-combination.
[0114] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it should be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Instead, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1. A first device for communication, include: at least one processor; as well as at least one memory including computer program code; The at least one memory and the computer program code are configured to, with the at least one processor, cause the first device to: receiving a request for allocated resources of the network slice from a second device; Obtaining security requirements for the network slice from the request; determining a list of security services based on the security requirements; Allocating a network slice instance that supports the list of security services; as well as transmitting an indication of the allocated network slice instance to the second device; The first device is a network device, the second device is another network device, the second device is capable of communicating with the first device to create a network slice instance through which a third device communicates, and the third device is a terminal device or another network device; The first device is caused to allocate the network slice instance by: Mapping the security service list to a network slice resource module; Get information about available network slice instances; Obtaining the security status of the available network slice instance; Determining whether the existing network slice instance meets the security requirements; Determining the existing network slice instance as an allocated resource of the requested network slice based on determining that the existing network slice instance meets the security requirement; or Based on determining that the existing network slice instance does not meet the profile of the network slice, a network slice instance is created based at least in part on the security requirements.
2. The first device according to claim 1, wherein the first device is caused to create the network slice instance by: Allocating multiple network slice subnet instances that meet the security requirements and required services; and The network slice instance is created by linking the multiple network slice subnet instances.
3. The first device according to claim 2, wherein the first device is further caused to allocate the plurality of network slice subnet instances by: Mapping the security service list to the multiple network slice subnet resource modules; Get information about available network slice subnet instances; Obtaining the security status of the available network slice subnet instance; Determine whether the existing network slice subnet instance meets the security requirements; According to determining that the existing network slice subnet instance meets the security requirement, determining the existing network slice subnet instance as an allocated resource of the requested network slice subnet; or Based on determining that the existing network slice subnet instance does not meet the profile of the network slice subnet, a network slice subnet instance is created based at least in part on the security requirements.
4. The first device according to claim 1, wherein the first device is further caused to: In response to monitoring data on the network slice instance, determining whether the security requirements of the allocated resources of the requested network slice are met; and Based on determining that the security requirements are not met, the allocated resources of the network slice are updated.
5. The first device according to claim 1, wherein the first device is further caused to: Detecting abnormal behavior of the third device by monitoring access data of the third device on the network slice instance; and A further indication of the detection of the abnormal behavior is transmitted to the second device.
6. The first device of claim 1, wherein the first device is further caused to: Mapping the security service list to a network slice resource module; and Obtaining the security status of one or more network slice instances; and The network slice instance is allocated based on the network slice resource module.
7. A second device for communication, include: at least one processor; as well as at least one memory including computer program code; The at least one memory and the computer program code are configured to, with the at least one processor, cause the second device to: generating a request for allocated resources of the network slice, the request indicating at least a security requirement; transmitting the request to the first device; and receiving, from the first device, an indication of an allocated network slice instance, the allocated network slice instance satisfying at least the security requirement; The first device is a network device, the second device is another network device, the second device is capable of communicating with the first device to create a network slice instance through which a third device communicates, and the third device is a terminal device or another network device; The allocated network slice instance is determined or created by: Map the security service list to the network slice resource module; Get information about available network slice instances; Obtaining the security status of the available network slice instance; Determining whether the existing network slice instance meets the security requirements; Determining the existing network slice instance as an allocated resource of the requested network slice based on determining that the existing network slice instance meets the security requirement; or Based on determining that the existing network slice instance does not meet the profile of the network slice, a network slice instance is created based at least in part on the security requirements.
8. The second device according to claim 7, wherein the second device is further caused to: Based on determining that the security requirements are not met, receiving further instructions for updating allocated resources for the network slice.
9. The second device according to claim 7, wherein the second device is further caused to: Another indication of detection of abnormal behavior of the third device is received from the first device.
10. A method for communication, include: At the first device, receiving a request for allocated resources of the network slice from the second device; Obtaining security requirements for the network slice from the request; determining a list of security services based on the security requirements; Allocating a network slice instance that supports the list of security services; as well as transmitting an indication of the allocated network slice instance to the second device; The first device is a network device, the second device is another network device, the second device is capable of communicating with the first device to create a network slice instance through which a third device communicates, and the third device is a terminal device or another network device; Wherein allocating the network slice instance comprises: Mapping the security service list to a network slice resource module; Get information about available network slice instances; Obtaining the security status of the available network slice instance; Determining whether the existing network slice instance meets the security requirements; Determining the existing network slice instance as an allocated resource for the requested network slice based on determining that the existing network slice instance meets the security requirements; or Based on determining that the existing network slice instance does not meet the profile of the network slice, a network slice instance is created based at least in part on the security requirements.
11. The method according to claim 10, wherein creating a network slice instance include: Allocate multiple network slice subnet instances that meet the security requirements and required services; as well as A network slice instance is created by linking the multiple network slice subnet instances.
12. The method according to claim 11, wherein the plurality of network slice subnet instances are allocated include: Mapping the security service list to the multiple network slice subnet resource modules; Get information about available network slice subnet instances; Obtaining the security status of the available network slice subnet instance; Determine whether the existing network slice subnet instance meets the security requirements; According to determining that the existing network slice subnet instance meets the security requirement, determining the existing network slice subnet instance as an allocated resource of the requested network slice subnet; or Based on determining that the existing network slice subnet instance does not meet the profile of the network slice subnet, a network slice subnet instance is created based at least in part on the security requirements.
13. The method according to claim 10, further comprising: include: In response to monitoring data on the network slice instance, determining whether the security requirement of the network slice is satisfied based on the data; as well as Based on determining that the security requirements are not met, the allocated resources of the network slice are updated.
14. The method according to claim 10, further comprising: include: Abnormal behavior of the third device is detected by monitoring access data of the third device on the network slice instance.
15. The method according to claim 10, further comprising: include: Mapping the security service list to a network slice resource module; as well as Get the security status of one or more network slice instances; as well as The network slice instance is allocated based on the network slice resource module.
16. A method for communication, include: At the second device, generating a request for allocated resources of the network slice, the request indicating at least a security requirement; transmitting the request to the first device; as well as receiving, from the first device, an indication of an allocated network slice instance, the allocated network slice instance satisfying at least the security requirement; The first device is a network device, the second device is another network device, the second device is capable of communicating with the first device to create a network slice instance through which a third device communicates, and the third device is a terminal device or another network device; The allocated network slice instance is determined or created by the following operations: Map the security service list to the network slice resource module; Get information about available network slice instances; Obtaining the security status of the available network slice instance; Determining whether the existing network slice instance meets the security requirements; Determining the existing network slice instance as an allocated resource of the requested network slice based on determining that the existing network slice instance meets the security requirement; or Based on determining that the existing network slice instance does not meet the profile of the network slice, a network slice instance is created based at least in part on the security requirements.
17. The method according to claim 16, further comprising: include: Based on determining that the security requirements are not met, receiving further instructions for updating allocated resources for the network slice.
18. The method according to claim 16, further comprising: include: Another indication of detection of abnormal behavior of the third device is received from the first device.
19. A device for communication, include: means for receiving, at a first device, from a second device, a request for allocated resources of a network slice; means for obtaining, from the request, security requirements of the network slice; means for determining a list of security services based on said security requirements; means for allocating a network slice instance supporting said list of security services; as well as means for transmitting an indication of the allocated network slice instance to the second device; The first device is a network device, the second device is another network device, the second device is capable of communicating with the first device to create a network slice instance through which a third device communicates, and the third device is a terminal device or another network device; The component for allocating a network slice instance supporting the security service list includes: A component for mapping the security service list to a network slice resource module; A component for obtaining information about available network slice instances; A component for obtaining the security status of the available network slice instance; A component for determining whether an existing network slice instance meets the security requirements; A component for determining the existing network slice instance as an allocated resource for the requested network slice based on determining that the existing network slice instance satisfies the security requirements; or A component for creating a network slice instance based at least in part on the security requirements in response to determining that the existing network slice instance does not meet the profile of the network slice.
20. An apparatus for communication, include: means for generating a request for allocated resources of a network slice, the request indicating at least a security requirement; means for transmitting the request to the first device; as well as means for receiving, from the first device, an indication of an allocated network slice instance, the allocated network slice instance satisfying at least the security requirement; The first device is a network device, the apparatus is another network device, the apparatus is capable of communicating with the first device to create a network slice instance through which a third device communicates, and the third device is a terminal device or another network device; The allocated network slice instance is determined or created by the following operations: Map the security service list to the network slice resource module; Get information about available network slice instances; Obtaining the security status of the available network slice instance; Determining whether the existing network slice instance meets the security requirements; Determining the existing network slice instance as an allocated resource of the requested network slice based on determining that the existing network slice instance meets the security requirement; or Based on determining that the existing network slice instance does not meet the profile of the network slice, a network slice instance is created based at least in part on the security requirements.
21. A computer-readable storage medium comprising program instructions stored thereon, which instructions, when executed by a device, cause the device to perform the method according to any one of claims 10 to 15.
22. A computer-readable storage medium comprising program instructions stored thereon, which instructions, when executed by an apparatus, cause the apparatus to perform the method according to any one of claims 16 to 18.
Citation Information
Patent Citations
Communication method and apparatus
CN109600769A
Security-based slice selection and assignment
WO2017200978A1