An end-to-end secure RAN slice deployment method and system based on OTN encryption
By adopting an OTN-based encryption-based RAN slice deployment method, the end-to-end security issue in RAN slice deployment is solved, achieving efficient and secure slice deployment and encrypted resource utilization, thereby improving network security and resource utilization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-19
- Publication Date
- 2026-03-17
AI Technical Summary
Existing RAN slice deployment methods struggle to achieve end-to-end security, especially lacking effective strategies against physical layer attacks and eavesdropping. Furthermore, there are no concrete solutions for applying OTN encryption technology in RAN slice deployment.
An end-to-end secure RAN slice deployment method based on OTN encryption is adopted. Through resource inspection, appropriate deployment of DU and CU, encryption processing, and routing bandwidth resource allocation of OTN line cards and EC, the security and efficient deployment of slices are ensured.
It achieves end-to-end security for RAN slices, while improving the utilization of encryption resources, maximizing the number of bearer slices, and enhancing network security and efficiency.
Smart Images

Figure CN115580875B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless communication technology, and more specifically, to an end-to-end secure RAN slice deployment method and system based on OTN encryption. Background Technology
[0002] In recent years, with the continuous development of 5G network technology, more and more different devices have accessed the network, bringing a large number of new mobile services with drastically different requirements for network performance indicators. To flexibly deploy services with different needs, network slicing technology has been proposed. The 5G Radio Access Network (RAN) also supports a network slicing architecture, dividing a single physical RAN infrastructure into multiple logical networks to meet the differentiated needs of services such as enhanced bandwidth, ultra-low latency, and massive connectivity. However, network slicing also blurs network boundaries and reduces network security. Currently, there is no good method to achieve end-to-end security for network slices. OTN (Optical Transport Network) encryption can directly encrypt data transmitted in the network, offering advantages such as low latency and low overhead. Furthermore, leveraging the traffic management capabilities of the OTN switching structure, it can improve the utilization rate of encryption devices and reduce the complexity of key management for subwavelength services. End-to-end security of network slices can be ensured by effectively using OTN encryption technology.
[0003] Existing RAN (Radio Network Network) security primarily focuses on slice isolation. By physically isolating the resources and traffic of different slices, resources between slices are prevented from interfering with each other, limiting potential network attacks to a single network slice and preventing attackers from impacting high-security slices by attacking low-security slices. However, there are no effective countermeasures against physical layer attacks and eavesdropping. Furthermore, existing slice allocation methods cannot guarantee absolute end-to-end security, for which OTN encryption may be an effective solution. However, there is no corresponding solution on how to efficiently and securely deploy RAN slices using OTN encryption technology. Therefore, current research lacks a concrete solution for the efficient and secure deployment of network slices in optical networks with OTN encryption capabilities. Summary of the Invention
[0004] To address the shortcomings of existing technologies, the present invention aims to provide an end-to-end secure RAN slice deployment method based on OTN encryption, which can efficiently deploy slices and utilize encrypted resources while achieving end-to-end security of RAN slices.
[0005] The present invention adopts the following technical solution.
[0006] An end-to-end secure RAN slice deployment method based on OTN encryption includes the following steps:
[0007] Step 1: After the network node initiates a RAN slice request, it checks whether the service initiation point has sufficient AAU resources. If not, it is determined that the slice is blocked; otherwise, proceed to Step 2.
[0008] Step 2: Deploy DU on the AE node or MN node for the RAN slice;
[0009] Step 3: Deploy CUs on the MN node or AE node for the RAN slice;
[0010] Step 4: For the selected deployment nodes, check in turn whether the transmission delay of each part is less than the maximum delay tolerated by the RAN slice. If it is not satisfied, return to step 2 to find the remaining nodes to deploy the RAN slice. If it is satisfied, perform routing bandwidth resource allocation.
[0011] Preferably, in step 1, the number of AAU resources is represented by resource blocks. The number of resource blocks used by each RAN slice is known. If the remaining AAU resources of the service initiating point are less than the resource blocks required by the RAN slice, it means that the service initiating point does not have enough AAU resources. At this time, the slice is blocked. Otherwise, proceed to step 2.
[0012] Preferably, step 2 further includes:
[0013] Step 2-1: Deploy DU for RAN slices, select AEs sequentially from the DU pre-selected resource set and check if there are sufficient computing resources;
[0014] Step 2-2: Determine whether the slice is a low-security slice or a high-security slice. If it is a high-security slice, proceed to step 2-3; otherwise, proceed directly to step 3.
[0015] Steps 2-3: Determine whether the high-security slice needs to be encrypted and perform security encryption constraint processing on the high-security slice that needs to be encrypted.
[0016] Preferably, step 2-1 further includes:
[0017] When selecting AEs from the DU pre-selected resource set, they are selected in the order of local AEs and adjacent AEs;
[0018] Determine whether the selected AE has sufficient computing resources, that is, whether the remaining computing resources of the selected AE are greater than the computing resources requested by the RAN slice;
[0019] If sufficient computing resources are available, deploy DU on the selected AE;
[0020] If there are insufficient computing resources, determine whether DU and CU can be co-located in the CU pre-selected resource set in the order of local MN and adjacent MN. If so, co-locate DU and CU on the MN in the CU pre-selected resource set; otherwise, consider the slice blocked and end the process.
[0021] Preferably, steps 2-3 further include:
[0022] For high-security slices, after selecting the AE, check whether the mid-transmission passes through an untrusted link. If it does, encryption needs to be performed on the selected AE.
[0023] If the high-security slice selects an adjacent AE, it is also necessary to check whether the forward pass passes through an untrusted link. If it passes through an untrusted link, encryption needs to be performed on the local AE and decrypted on the selected adjacent AE.
[0024] If DU and CU are co-located in MN, then there is no intermediate transmission process. It is necessary to check whether the fronthaul passes through an untrusted link. If it does, local AE encryption is also required.
[0025] Preferably, step 3 further includes:
[0026] Step 3-1: Deploy CUs for slices by sequentially selecting MNs from the CU pre-selected resource set and checking whether there are sufficient computing resources.
[0027] Step 3-2: Determine if the slice is a high-security slice. If so, proceed to step 3-3.
[0028] Step 3-3: Perform security encryption constraint processing on the high-security slice.
[0029] Preferably, step 3-1 further includes,
[0030] When deploying a CU, resources are selected from the CU pre-selection set in the order of local MN and adjacent MN.
[0031] Check if the selected MN has sufficient computing resources. If it does, deploy the CU on the selected MN.
[0032] If there are insufficient computing resources, attempt to co-configure the DU and CU in the pre-selected resource set of DU in the order of local AE and adjacent AE. If it is possible, co-configure the DU and CU in the AE. If it is not possible to co-configure the DU and CU in the AE, it indicates that the slice is blocked and the process ends.
[0033] Preferably, step 3-3 further includes:
[0034] Step 3-3-1: For the high-security slice, check whether the MN selected in step 3-1 has enough encryption resources to encrypt the return. If there are enough encryption resources to encrypt the return, the high-security slice is encrypted and the process proceeds to step 3-3-2. If there are not enough encryption resources to encrypt the return, the slice is considered blocked and the process ends.
[0035] Step 3-3-2: Determine whether an adjacent MN was selected when deploying the CU. If no adjacent MN was selected when deploying the CU, proceed to step 3-3-3. If an adjacent MN was selected, further check whether the selected adjacent AE has sufficient encryption resources to ensure that the mid-transmission is encrypted and transmitted in the aggregation ring. If the selected adjacent AE has sufficient encryption resources, encrypt the high-security slice and proceed to step 3-3-3. Otherwise, return to step 2 to find the remaining methods to deploy slices.
[0036] Step 3-3-3: Determine whether the DU and CU are co-located on the AE when deploying the CU. If the DU and CU are not co-located on the AE, end step 3-3. If the DU and CU are co-located on the AE, further determine whether the selected AE node has sufficient encryption resources. If it has sufficient encryption resources, encrypt the high-security slice. Otherwise, return to step 2 to find the remaining methods to deploy the slice.
[0037] Preferably, step 4, which involves allocating routing bandwidth resources, further includes:
[0038] For each part of the transmission traffic, check whether the current rate of the enabled OTN line card has enough remaining capacity. If there is enough capacity, prioritize using the enabled OTN line card to transmit traffic, thereby improving resource utilization. If there is not enough capacity, switch to a higher rate transmission until the maximum transmission rate of the OTN line card is reached.
[0039] If the OTN line card's transmission rate is already at its maximum, check if there is an idle OTN line card. If there is an idle OTN line card, activate that idle OTN line card and transmit traffic at its minimum rate.
[0040] If there are no free OTN line cards, repeat the remaining options in steps 2 and 3. That is, if there are other remaining AE or MN nodes available in steps 2 and 3, try to select and redeploy them until all methods have been tried. If there are no remaining options in steps 2 and 3 or the slice still cannot be deployed after retrying, it means that the slice is blocked.
[0041] The present invention also provides an end-to-end secure RAN slice deployment system based on OTN encryption, comprising: a resource inspection module, a DU deployment module, a CU deployment module, an encryption module, and a resource allocation module;
[0042] The resource check module is used to check whether the business initiation point has sufficient AAU resources.
[0043] The DU deployment module enables the deployment of DUs for RAN slices on AE or MN nodes;
[0044] The CU deployment module can deploy CUs on MN nodes or AE nodes for RAN slices;
[0045] The encryption module is used to determine whether a slice needs to be encrypted and to encrypt high-security slices.
[0046] The resource allocation module can allocate routing bandwidth resources for OTN line cards and ECs.
[0047] The present invention also provides a terminal, including a processor and a storage medium;
[0048] The storage medium is used to store instructions;
[0049] The processor is configured to operate according to the instructions to execute the steps of the end-to-end secure RAN slice deployment method based on OTN encryption.
[0050] The present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the OTN-based end-to-end secure RAN slice deployment method.
[0051] The beneficial effects of this invention are that, compared with the prior art, the RAN slice deployment method proposed in this invention can select nodes with encryption capabilities to deploy DU (Distributed Unit) and CU (Centralized Unit) for slices according to slice security requirements, and select appropriate traffic routing methods to improve the utilization rate of encryption resources; at the same time, it can also appropriately select co-location or separate deployment methods for slices to achieve the effect of maximizing the number of slices carried in the network. This invention achieves end-to-end security of RAN slices while efficiently deploying slices and utilizing encryption resources. Attached Figure Description
[0052] Figure 1 This is a schematic diagram of the overall process of the end-to-end secure RAN slice deployment method based on OTN encryption proposed in this invention;
[0053] Figure 2 This is a schematic diagram of the 5GRAN baseband processing function segmentation in this invention;
[0054] Figure 3 This is a schematic diagram of the separate architecture and integrated architecture of DU and CU deployment in this invention;
[0055] Figure 4This is a schematic diagram of the simulation experiment in this invention;
[0056] Figure 5 This is a schematic diagram of the structure of the end-to-end secure RAN slice deployment system based on OTN encryption proposed in this invention. Detailed Implementation
[0057] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this invention. The embodiments described in this application are merely some embodiments of this invention, and not all embodiments. Based on the spirit of this invention, other embodiments obtained by those skilled in the art without creative effort are all within the protection scope of this invention.
[0058] like Figure 1 As shown, this invention proposes an end-to-end secure RAN slice deployment method based on OTN encryption, which specifically includes the following steps:
[0059] Step 1: After the network node initiates a RAN slice request, it checks whether the service initiation point has sufficient AAU resources. If not, it is determined that the slice is blocked; otherwise, proceed to Step 2.
[0060] like Figure 2 As shown, the architecture adopted in the RAN slicing deployment of this invention is a three-layer architecture consisting of AAU (Active Antenna Unit), DU (Distributed Unit), and CU (Centralized Unit). RAN slices are deployed in the order of AAU-DU-CU-Core Network (RRC). Service traffic flows from AAU through DU and CU in sequence, and is finally transmitted to the core network, with the ME node as the entry point for the core network.
[0061] The service initiation point is the node that initiates the RAN slice request, and AAU needs to be deployed on the initiating node. Each node has limited AAU resources, which can be represented by resource blocks (RBs). Each RAN slice uses a certain number of resource blocks. If the remaining AAU resources of the service initiation point are insufficient to provide for the RAN slice, it means that the service initiation point does not have enough AAU resources, and the slice is blocked.
[0062] Step 2: Deploy DUs on AE or MN nodes for RAN slices;
[0063] Specifically, for the requested RAN slices, DU and CU need to be deployed on AE and MN, and then transmitted to ME. Slices are also divided into high-security slices with security requirements and low-security slices without security requirements. Only traffic transmitted over untrusted links from high-security slices needs to be encrypted. Slice isolation is also considered; slices of different security levels cannot use the same computing resources on the same server.
[0064] Furthermore, depending on the different security requirements of RAN slices, RAN slices include low-security slices and high-security slices. For each slice, DU and CU have a pre-selected resource set. For DU, the pre-selected resource set includes the local AE and neighboring AEs. For CU, the pre-selected resource set includes the local MN and neighboring MNs. The pre-selected resource set is a known quantity.
[0065] like Figure 3 As shown, using NFV (Network Functions Virtualization) technology, functional instances of DU and CU can be deployed on different virtual machines of a general-purpose server. At the same time, CU can be connected separately to multiple DUs to achieve unified and centralized management of DUs, or it can be integrated with DUs to realize all the functions of the protocol stack to meet the needs of special scenarios.
[0066] Specifically, step 2 also includes the following steps:
[0067] Step 2-1, deploy DU for RAN slice, including sequentially selecting AE in the DU preselection resource set and checking whether there are sufficient computing resources;
[0068] Specifically, when selecting AEs in the DU pre-selected resource set, they are selected in the order of local AEs and adjacent AEs.
[0069] The computing resources are the unused computing resources on the servers of the AE nodes in each pre-selected resource set, i.e., the remaining computing resources. These computing resources are quantifiable, and the amount of computing resources requested by the RAN slice is a known quantity. If the remaining computing resources are greater than the computing resources requested by the RAN slice, it means that there are sufficient computing resources; otherwise, it means that there are not sufficient computing resources.
[0070] If sufficient computing resources are available, deploy DU on the selected AE;
[0071] If there are not enough computing resources, determine whether MN can be selected from the CU pre-selected resource set to co-configure DU and CU. If so, co-configure DU and CU on MN in the CU pre-selected resource set; otherwise, consider the slice blocked and end the process.
[0072] When selecting MNs in the CU pre-selection resource set, the selection should be performed in the order of local MNs and adjacent MNs.
[0073] Understandably, for a single RAN slice, only one AE or MN node is selected for deployment when deploying a DU.
[0074] Step 2-2: Determine whether the RAN slice is a low-security slice or a high-security slice. If it is a high-security slice, proceed to step 2-3; otherwise, proceed directly to step 3.
[0075] The security requirement level of a slice is related to information such as the request type, application scenario, or customer requirements. When a network node initiates a RAN slice request, its security level, whether high or low, is a known parameter, meaning that the slice is known to be a high-security slice or a low-security slice.
[0076] The high-security slice and the low-security slice have different business security requirements. In this invention, the high-security slice needs to be encrypted when passing through an untrusted link, while the low-security slice does not need to be encrypted when passing through an untrusted link.
[0077] Steps 2-3: Determine whether the high-security slice needs to be encrypted and perform security encryption constraint processing on the high-security slice that needs to be encrypted;
[0078] Specifically, for high-security slices, after selecting the AE, it is necessary to check whether the midhaul passes through an untrusted link. If it does, encryption needs to be performed on the selected AE.
[0079] If the high-security slice selects an adjacent AE, it is also necessary to check whether the forward pass passes through an untrusted link. If it does, encryption needs to be performed on the local AE and decrypted on the selected adjacent AE.
[0080] If DU and CU are co-located in MN, then there is no intermediate transmission process. It is necessary to check whether the fronthaul passes through an untrusted link. If it does, local AE encryption is also required.
[0081] Among them, the transmission from AAU to DU is the fronthaul, the transmission from DU to CU is the midhaul, and the transmission from CU to the 5G core network is the backhaul.
[0082] Step 3: Deploy CUs on MN or AE nodes for RAN slices;
[0083] Specifically, step 3 also includes the following steps:
[0084] Step 3-1: Deploy CUs for slices by sequentially selecting MN nodes from the CU pre-selected resource set and checking whether there are sufficient computing resources.
[0085] When deploying a CU, the CU is selected from the pre-selected resource set in the order of local MN and adjacent MN. The selected MN node is checked to see if there are enough computing resources. If there are enough computing resources, the CU is deployed on the selected MN node.
[0086] If there are insufficient computing resources, the DU and CU will be co-located in the DU pre-selected resource set in the order of local AE and adjacent AE. First, try to co-locate on the local AE. If it is possible, then co-locate the DU and CU on the local AE. Otherwise, check if it can be co-located on the adjacent AE. If it is possible, then co-locate on the adjacent AE. If it is not possible to co-locate the DU and CU on the AE node, it means that the slice is blocked and the process ends.
[0087] Step 3-2: Determine whether the slice is a high-security slice. If so, proceed to step 3-3; otherwise, proceed to step 4.
[0088] Step 3-3: Perform security encryption constraint processing on the high-security slice;
[0089] Specifically, step 3-3 also includes:
[0090] Step 3-3-1: For the high-security slice, check whether the MN selected in step 3-1 has enough encryption resources to encrypt the return. If there are enough encryption resources to encrypt the return, the high-security slice is encrypted and the process proceeds to step 3-3-2. If there are not enough encryption resources to encrypt the return, the slice is considered blocked and the process ends.
[0091] The encryption resource is the unused EC capacity in the server on each pre-selected resource set node AE, i.e., the remaining EC capacity. The EC capacity is quantifiable. Encryption requires traffic to be transmitted through the EC, consuming the EC capacity. The EC capacity required for the RAN slice is a known amount. If the remaining EC capacity is greater than the EC capacity required for the RAN slice, it means that there is sufficient encryption resource; otherwise, it means that there is not enough encryption resource.
[0092] Step 3-3-2: Determine whether an adjacent MN was selected when deploying the CU in step 3-1. If an adjacent MN was selected, it is necessary to further check whether the selected adjacent AE has sufficient encryption resources to transmit the encrypted mid-transmission in the aggregation ring. If the selected adjacent AE has sufficient encryption resources, the high-security slice is encrypted and the process proceeds to step 3-3-3. Otherwise, return to step 2 to find the remaining nodes to deploy the slice.
[0093] If an adjacent MN was not selected when deploying the CU in step 3-1, proceed to step 3-3-3;
[0094] In this context, finding remaining nodes to deploy slices refers to selecting nodes in the order of local AE, neighboring AE, local MN, and neighboring MN when deploying DU for RAN slices in step 2. If there are still remaining selectable nodes, then try to select the remaining nodes to deploy DU for RAN slices.
[0095] Step 3-3-3: Determine whether the DU and CU were co-located on the AE when deploying the CU in step 3-1. If the DU and CU were co-located on the AE, further determine whether the selected AE node has sufficient encryption resources. If it has sufficient encryption resources, encrypt the high-security slice; otherwise, return to step 2 to find the remaining methods to deploy the slice.
[0096] If DU and CU are not set together in AE, then step 3-3 ends.
[0097] Step 4: For the selected deployment nodes, check whether the transmission latency of each part is less than the maximum latency that the slice can tolerate. If it does not meet the requirement, return to Step 2 and Step 3 to find the remaining nodes to deploy the slice. If it meets the requirement, allocate routing bandwidth resources.
[0098] Specifically, the deployment location refers to the selected DU deployment node and CU deployment node. The transmission includes fronthaul, midhaul and backhaul. For different slice types, the latency requirements of each part are known information, that is, the latency constraints are known when the slice request is initiated.
[0099] Network nodes are equipped with OTN line cards, which convert electrical layer data into optical layer traffic. This converted traffic can then be transmitted within the OTN network. OTN is a transport network based on wavelength division multiplexing (WDM) technology, organizing the network at the optical layer. It can carry various services and provide reliable end-to-end optical channels to ensure the quality of service for different services. OTN combines the advantages of optical and electrical domain processing, providing massive transmission capacity and fully transparent end-to-end wavelength-level connections. Simultaneously, OTN switching technology ensures sub-wavelength-level service aggregation and routing capabilities. However, most widely used fiber optic channels lack physical layer security, making them vulnerable to serious attacks. Although 5G networks typically encrypt the application layer, fiber optic transmission is essentially undefended, making it easy for attackers to eavesdrop and intercept the data. Malicious users can exploit these vulnerabilities to conduct difficult-to-detect eavesdropping. Facing the risks of information hijacking and cross-connection, research into physical layer security schemes is crucial to improving the security of communication systems. OTN encryption technology uses an encryption board (EC) to encrypt OTN payload frames, offering advantages such as high throughput, low latency, and low encryption overhead. This invention utilizes OTN switching technology to achieve the aggregation and isolation of slice traffic during slice deployment, and employs OTN encryption to ensure end-to-end slice security.
[0100] In this embodiment, encryption cards are used for encryption. These cards typically have several rated transmission rates, matching the OTN line cards, and can be flexibly deployed in existing OTN architectures. However, due to cost and other reasons, not all nodes in a real network are equipped with encryption cards; they are deployed only on a subset of network nodes. The security levels of different links also vary, categorized as trusted and untrusted links. For example, links on the aggregation ring, due to their aggregation and transmission of more data, may be prime targets for malicious attackers, resulting in lower security levels. Therefore, trusted and untrusted links are distributed on the access ring, while all links on the aggregation ring are untrusted. In summary, some AE nodes in the network scenario are equipped with encryption cards, which is related to the distribution of untrusted links on the access ring. All MN nodes are equipped with encryption cards, enabling traffic encryption, and the ME has sufficient computing and encryption resources.
[0101] This includes allocating routing bandwidth resources, which involves selecting the necessary OTN line cards and encryption cards for RAN slice transmission, selecting the corresponding transmission rates, and choosing the correct transmission paths; it also includes:
[0102] For each part of the transmission traffic, check whether the current rate of the enabled OTN line card has enough remaining capacity. If there is enough capacity, prioritize using the enabled OTN line card to transmit traffic, thereby improving resource utilization. If there is not enough capacity, switch to a higher rate transmission until the maximum transmission rate of the OTN line card is reached.
[0103] If the OTN line card's transmission rate is already at its maximum, check if there is an idle OTN line card. If there is an idle OTN line card, activate that idle OTN line card and transmit traffic at its minimum rate.
[0104] If there are no free OTN line cards, repeat the remaining options in steps 2 and 3. That is, if there are other remaining AE or MN nodes available in steps 2 and 3, try to select and redeploy them until all methods have been tried. If there are no remaining options in steps 2 and 3 or the slice still cannot be deployed after retrying, it means that the slice is blocked.
[0105] Furthermore, EC can be used in conjunction with OTN line cards to enhance the encryption of electrical layer data. If an EC is deployed in a network node, for traffic aggregation through the EC, all traffic that requires encryption slices will first be aggregated at the switch, and then the aggregated traffic will be encrypted through the EC. Only the encrypted traffic can be aggregated at the switch with other traffic that does not require encryption slices. Finally, the total aggregated traffic will be transmitted through the OTN line card.
[0106] High-security slices are also constrained by encrypted resources. According to steps 2-3 and 3-3, if encryption is required on a certain AE or MN node, then that node must be configured with an EC. At the same time, the remaining capacity of the EC must be sufficient to transmit the resources that the slice needs to be encrypted. If the remaining capacity of the EC is insufficient, first try adjusting the EC to a higher rate. If the highest rate has been reached, then try using an idle EC. If it still cannot be found, repeat steps 2 and 3 for the remaining node options until all methods have been tried. If deployment still cannot be completed after traversing all methods, the slice will be blocked.
[0107] This invention addresses 5G RAN slicing. Through the technologies described above, 5G RAN slices can be flexibly deployed in the network, improving the utilization of heterogeneous resources. However, this also reduces network security. The solution to network slicing security issues in this invention is slice isolation, which isolates the RAN functions and traffic of different slices from each other, allowing each slice to operate on dedicated physical resources.
[0108] like Figure 5 As shown, the present invention also proposes an end-to-end secure RAN slice deployment system based on OTN encryption. The above-mentioned RAN slice deployment method can be implemented based on this system. Specifically, the system includes a resource inspection module, a DU deployment module, a CU deployment module, an encryption module, and a resource allocation module.
[0109] The resource check module is used to check whether the business initiation point has sufficient AAU resources.
[0110] The DU deployment module enables the deployment of DUs for RAN slices on AE or MN nodes;
[0111] The CU deployment module can deploy CUs on MN nodes or AE nodes for RAN slices;
[0112] The encryption module is used to determine whether a slice needs to be encrypted and to encrypt high-security slices.
[0113] The resource allocation module can allocate routing bandwidth resources for OTN line cards and ECs.
[0114] Simulation experiment:
[0115] To verify the effectiveness of the method of the present invention, the following experiments were conducted: Figure 4As shown, the convergence ring is simplified to a single link from MN to ME. AE1 has encryption capabilities, and the link from AE1 to MN is an untrusted link. The computing resources in the server of AE2 are already fully utilized. Assuming that the AAU resources of both AE1 and AE2 are sufficient, then sufficient AAU resources can be found for all slice requests initiated by AE1 and AE2 through step 1. Since slice 1 and slice 2 in the experiment are both high-security slices initiated from the AAU to which AE2 belongs, slice 1 and slice 2 are deployed according to the deployment scheme in steps 2 to 4 respectively:
[0116] For slice 1, in step 2, we first try to deploy DU on AE2. Because of insufficient resources, we then try to deploy DU on the adjacent AE1. After confirming that there are enough resources, in step 3, we try to deploy CU on MN. MN has enough resources. After confirming the locations of DU and CU, we proceed to step 4. After confirming that the latency constraint is met, because the link from AE1 to MN is untrusted, the mid-transmission of slice 1 needs to be encrypted.
[0117] For slice 2, in step 2, AE2 and AE1 do not have enough resources to deploy their DU, so we try to set the DU and CU together in MN. In this way, the CU position has been selected and step 3 is skipped. After confirming the latency constraints in step 4, deployment is carried out.
[0118] Furthermore, slice 3 in the experiment is a high-security slice initiated from AE1. In step 2, DU was selected to be deployed locally on AE1. In step 3, when CU was attempted to be deployed on MN, since MN did not have enough resources to deploy CU, it was attempted to co-locate DU and CU on AE1. After confirming the latency constraint in step 4, since the backhaul was directly transmitted from AE1 to ME, passing through the untrusted link from MN to ME, the data was directly encrypted on AE1.
[0119] It is important to note that if AE1 lacks encryption capabilities, slice 3 will be blocked because it will be unable to transmit encrypted resources within the aggregation ring. Furthermore, because the midhaul (AE1 to MN) of slice 1 and the backhaul (AE1 to ME) of slice 3 have different destination nodes, they cannot be transmitted on the same OTN line card after aggregation at the switch. However, since the backhauls of slices 1 and 2 are both transmitted from MN to ME, they can be aggregated at the switch first and then transmitted via the OTN line card.
[0120] The beneficial effects of this invention are that, compared with the prior art, the method proposed in this invention can select nodes with encryption capabilities to deploy DU and CU for slices according to slice security requirements, and select appropriate traffic routing methods to improve the utilization rate of encryption resources. Simultaneously, it selects appropriate co-location or separate deployment methods for DU and CU for slices, achieving the effect of maximizing the number of slices carried in the network. While achieving end-to-end security of RAN slices, it efficiently deploys slices and utilizes encryption resources.
[0121] Definition of the noun:
[0122] OTN: Optical Transport Network;
[0123] RAN: Radio Access Network;
[0124] AAU: Active Antenna Unit;
[0125] DU: Distributed Unit;
[0126] CU: Centralized Unit;
[0127] AE: Access Edge;
[0128] MN: Metro Node;
[0129] ME: Metro Edge;
[0130] NFV: Network Functions Virtualization;
[0131] EC: Encryption Card.
[0132] This disclosure can be a system, method, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for causing a processor to implement various aspects of this disclosure.
[0133] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.
[0134] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0135] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing state information from the computer-readable program instructions to implement various aspects of this disclosure.
[0136] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0137] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processor of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner; thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0138] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.
[0139] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.
Claims
1. A method for end-to-end secure RAN slice deployment based on OTN encryption, characterized in that, The method comprises the following steps: Step 1, after the network node initiates the RAN slice request, checking whether the service initiation point has sufficient AAU resources, if not, determining that the slice is blocked, otherwise, entering step 2; Step 2, deploying a DU for the RAN slice on an AE node or an MN node; The step 2 further comprises: Step 2-1, deploying the DU for the RAN slice, sequentially selecting an AE in a DU preselected resource set and checking whether there is sufficient computing resource; The step 2-1 further comprises: When selecting the AE in the DU preselected resource set, selecting the AE in the order of the local AE and the adjacent AE; Determining whether the selected AE has sufficient computing resource, that is, whether the remaining computing resource of the selected AE is greater than the computing resource required by the RAN slice request; If there is sufficient computing resource, deploying the DU on the selected AE; If there is not sufficient computing resource, determining whether the DU and the CU can be jointly set in the CU preselected resource set in the order of the local MN and the adjacent MN, if yes, jointly setting the DU and the CU on the MN in the CU preselected resource set, otherwise, considering that the slice is blocked and ending the process; Step 2-2, determining whether the slice is a low-security slice or a high-security slice, if it is a high-security slice, entering step 2-3, otherwise, directly entering step 3; Step 2-3, determining whether the high-security slice needs to be encrypted and performing security encryption constraint processing on the high-security slice that needs to be encrypted; The step 2-3 further comprises: For the high-security slice, after the AE is selected, checking whether the intermediate transmission passes through an untrusted link, if yes, the encryption needs to be performed on the selected AE; If the adjacent AE is selected for the high-security slice, further checking whether the intermediate transmission passes through an untrusted link, if yes, the encryption needs to be performed on the local AE and the decryption needs to be performed on the selected adjacent AE; If the DU and the CU are jointly set on the MN, at this time, there is no intermediate transmission process, it is needed to check whether the intermediate transmission passes through an untrusted link, if yes, the encryption needs to be performed on the local AE; Step 3, deploying a CU for the RAN slice on an MN node or an AE node; The step 3 further comprises: Step 3-1, deploying the CU for the slice, sequentially selecting an MN in a CU preselected resource set and checking whether there is sufficient computing resource; Step 3-2, determining whether the slice is a high-security slice, if yes, entering step 3-3; Step 3-3, performing security encryption constraint processing on the high-security slice; The step 3-1 further comprises, When deploying the CU, sequentially selecting the MN in the order of the local MN and the adjacent MN in the CU preselected resource set; Checking whether the selected MN has sufficient computing resource, if yes, deploying the CU on the selected MN; If there is not sufficient computing resource, trying to jointly set the DU and the CU in the DU preselected resource set in the order of the local AE and the adjacent AE, if yes, jointly setting the DU and the CU on the AE, if no, jointly setting the DU and the CU on the AE, indicating that the slice is blocked and ending the process; The step 3-3 further comprises: Step 3-3-1, for high-security slices, check whether the MN selected in step 3-1 has enough encryption resources to encrypt the backhaul, if there are enough encryption resources to encrypt the backhaul, then encrypt the high-security slice and enter step 3-3-2, if there are not enough encryption resources to encrypt the backhaul, it is considered that the slice is blocked, and the process ends; Step 3-3-2, determine whether the adjacent MN is selected when deploying the CU, if the adjacent MN is not selected when deploying the CU, enter step 3-3-3, if the adjacent MN is selected, further check whether the selected adjacent AE has enough encryption resources to enable transmission after encryption, if the selected adjacent AE has enough encryption resources, encrypt the high-security slice and enter step 3-3-3, otherwise return to step 2 to find the remaining method to deploy the slice; Step 3-3-3, determine whether the DU and CU are co-located with the AE when deploying the CU, if the DU and CU are not co-located with the AE, end step 3-3, if the DU and CU are co-located with the AE, further determine whether the selected AE node has enough encryption resources, if the selected AE node has enough encryption resources, encrypt the high-security slice, otherwise return to step 2 to find the remaining method to deploy the slice; Step 4, for the selected deployment node, check whether each part of the transmission delay meets the requirement of being less than the maximum delay tolerated by the RAN slice, if not, return to step 2 to find the remaining node to deploy the RAN slice, if yes, perform routing bandwidth resource allocation.
2. The end-to-end secure RAN slice deployment method based on OTN encryption according to claim 1, characterized in that, In step 1, the number of resources of the AAU is represented by resource blocks, and the number of resource blocks used by each RAN slice is known, if the remaining AAU resources of the service initiation point are less than the required resource blocks of the RAN slice, it indicates that the service initiation point does not have enough AAU resources, at this time the slice is blocked, otherwise enter step 2.
3. The end-to-end secure RAN slice deployment method based on OTN encryption according to claim 1, characterized in that, In step 4, the routing bandwidth resource allocation further includes: For each part of the transmission flow, check whether there is enough capacity in the current rate of the enabled OTN line card, if yes, prefer to use the enabled OTN line card to transmit the flow, thereby improving the resource utilization, if no, replace it with a larger rate transmission until the maximum transmission rate of the OTN line card is reached; If the transmission rate of the OTN line card is already the maximum rate, check whether there is an idle OTN line card, if yes, enable the idle OTN line card and transmit the flow at its minimum rate; If there is no idle OTN line card, repeat steps 2 and 3 to select the remaining options, i.e., if there are other remaining options in steps 2 and 3, try to select and redeploy, until all methods are tried, if there are no remaining options in steps 2 and 3 or the slice cannot be deployed after reattempting, it indicates that the slice is blocked.
4. An OTN encryption-based end-to-end secure RAN slicing deployment system based on the method of any of claims 1-3, characterized in that, including: A resource checking module, a DU deployment module, a CU deployment module, an encryption module and a resource allocation module; The resource checking module is configured to check whether the service initiation point has sufficient AAU resources; The DU deployment module is configured to deploy a DU for a RAN slice at an AE node or an MN node; The CU deployment module is configured to deploy a CU for a RAN slice at an MN node or an AE node; The encryption module is configured to determine whether encryption is required for a slice and to perform encryption processing on a high-security slice; The resource allocation module is configured to perform routing bandwidth resource allocation for an OTN line card and an EC. 5.A terminal comprising a processor and a storage medium; characterized in that: The storage medium is configured to store instructions; The processor is configured to operate according to the instructions to perform the steps of the end-to-end secure RAN slice deployment method based on OTN encryption according to any one of claims 1-3.
6. A computer readable storage medium having stored thereon a computer program, characterized in that The program is executed by the processor to implement the steps of the end-to-end secure RAN slice deployment method based on OTN encryption according to any one of claims 1-3.