Method and apparatus for isolation support in network slicing
By mapping slice isolation policies to resource and service isolation policies in network slices, the isolation problem between network slices is solved, fine-grained isolation is achieved, and network utilization and service quality are improved.
Patent Information
- Application Number
- CN202080102973.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-15
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2040-07-15
AI Technical Summary
The prior art is difficult to implement fine-grained isolation strategies in network slices, resulting in the inability to effectively isolate the network slices of different rental users, affecting network utilization and service quality.
By receiving the slicing isolation policy of the network slice subnet, it is mapped to the network resource isolation policy and the service isolation policy, and mapped to the network resource allocation policy and the data service forwarding policy respectively, to ensure that the network slice subnet that meets the isolation requirements is created in the transmission network domain, and the implementation of the isolation policy is monitored through the isolation monitoring function.
It implements a fine-grained isolation strategy in the transmission network domain, meets the isolation needs of different rental users, and improves network utilization and service quality.
Smart Images

Figure CN115843429B_ABST
Abstract
Description
Technical Field
[0001] The various example embodiments described in this application generally relate to communication technology, and more specifically, to communication methods and devices that support fine-grained isolation strategies in network slicing. Background Art
[0002] In this specification and / or drawings, certain abbreviations may be defined as follows:
[0003] ACL Access Control List
[0004] AN Access Network
[0005] CN Core Network
[0006] DSCP Differentiated Services Code Point
[0007] E2E End-to-End
[0008] NF Network Function
[0009] NFV Network Function Virtualization
[0010] NR New Radio
[0011] NS Network Slicing
[0012] NSMF Network Slicing Management Function
[0013] NSI Network Slicing Example
[0014] NSS Network Slicing Subnet
[0015] NSSMF Network Slicing Subnet Management Function
[0016] NSSI Network Slicing Subnet Example
[0017] NRM Network Resource Model
[0018] SDN Software Defined Networking
[0019] SMF session management functions
[0020] TN transmission network
[0021] VLAN Virtual Local Area Network
[0022] UPF User Plane Function
[0023] 5G NR is designed for a wide range of use cases, including enhanced mobile broadband (eMBB), massive machine-type communications (eMTC), and ultra-reliable low-latency communications (uRLLC). Many of these scenarios require different types of functionality and networks in terms of mobility, security, policy control, latency, coverage, and reliability. Therefore, network slicing has been proposed, slicing a single physical network into multiple virtual end-to-end networks to carry different types of services with varying characteristics and requirements. Network slicing enables diverse services from different companies and industries to be provided by a single physical network, significantly improving network utilization. Summary of the Invention
[0024] The following provides a brief summary of exemplary embodiments to provide a basic understanding of some aspects of various embodiments. It should be noted that this summary is not intended to identify key features of essential elements or define the scope of the embodiments. Its sole purpose is to introduce some concepts in a simple form as a prelude to the more detailed description provided below.
[0025] In a first aspect, an example embodiment of a method for isolating a network slice is provided. The method may include: receiving a slice isolation policy of a network slice subnet (NSS) in a transport network (TN) domain; mapping the slice isolation policy to a network resource isolation policy and a traffic isolation policy; and mapping the network resource isolation policy and the traffic isolation policy to a network resource allocation policy and a data traffic forwarding policy, respectively. The network resource allocation policy and the data traffic forwarding policy are applied to the creation of the TN NSS.
[0026] In a second aspect, an example embodiment of a network slicing isolation method is provided. The method may include: creating a data transmission channel for an NSS in a TN that complies with a TN NSS isolation policy; collecting isolation-related data of the TN NSS during operation of the TN NSS; and reporting the collected isolation-related data to an isolation monitoring function at a higher layer.
[0027] In a third aspect, an example embodiment of a method for monitoring network slice isolation is provided. The method may include: sending a request to a transport control and management function of a TN to collect isolation monitoring data of an NSS; receiving the isolation monitoring data of the TN NSS from the transport control and management function; analyzing the isolation monitoring data during operation of the TN NSS to determine whether a slice isolation policy of the TN NSS is satisfied; and reporting the analysis result of the isolation monitoring data to an upper-layer isolation monitoring function.
[0028] In a fourth aspect, an example embodiment of a method for monitoring network slice isolation is provided. The method may include: receiving isolation monitoring information of an NSS of an NS; determining whether a slice isolation policy is properly implemented during operation of the NSS based on the received isolation monitoring information, the received isolation monitoring information including: analysis results of isolation monitoring data of attributes extracted from the slice isolation policy; and generating an alarm when it is determined that at least a portion of the slice isolation policy is not properly implemented.
[0029] In a fifth aspect, an example embodiment of a network function unit is provided. The network function unit may include: at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, using the at least one processor, cause the network function unit to: receive a slice isolation policy of an NSS in a TN domain; map the slice isolation policy to a network resource isolation policy and a service isolation policy; and map the network resource isolation policy and the service isolation policy to a network resource allocation policy and a data service forwarding policy, respectively. The network resource allocation policy and the data service forwarding policy may be applied to the creation of a TN NSS.
[0030] In a sixth aspect, an example embodiment of a network function unit is provided. The network function unit may include: at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, using the at least one processor, cause the network function unit to: create a data transmission channel for an NSS in a TN that complies with a TN NSS isolation policy; collect isolation-related data of the TN NSS during TN NSS operation; and report the collected isolation-related data to an upper-layer isolation monitoring function.
[0031] In a seventh aspect, an example embodiment of a network function unit is provided. The network function unit may include: at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, using the at least one processor, cause the network function unit to: send a request to a transmission control and management function of a TN to collect isolation monitoring data of an NSS; receive the isolation monitoring data of the TN NSS from the transmission control and management function; during operation of the TN NSS, analyze the isolation monitoring data to determine whether a slice isolation policy of the TN NSS is satisfied; and report the analysis result of the isolation monitoring data to an upper-layer isolation monitoring function.
[0032] In an eighth aspect, an example embodiment of a network function unit is provided. The network function unit may include: at least one processor and at least one memory including computer program code. The at least one memory and the computer program code are configured to, using the at least one processor, cause the network function unit to: receive isolation monitoring information of an NSS of an NS; determine whether a slice isolation policy is properly implemented during operation of the NSS based on the received isolation monitoring information, wherein the received isolation monitoring information includes: analysis results of isolation monitoring data of attributes extracted from the slice isolation policy; and generate an alarm when it is determined that at least a portion of the slice isolation policy is not properly implemented.
[0033] In a ninth aspect, an example embodiment of a device for isolating a network slice is provided. The device for isolating a network slice may include: a device for receiving a slice isolation policy of an NSS in a TN domain; a device for mapping the slice isolation policy to a network resource isolation policy and a service isolation policy; and a device for mapping the network resource isolation policy and the service isolation policy to a network resource allocation policy and a data service forwarding policy, respectively. The network resource allocation policy and the data service forwarding policy are applied to the creation of the TN NSS.
[0034] In a tenth aspect, an example embodiment of an apparatus for isolating a network slice is provided. The apparatus for isolating a network slice may include: a device for creating a data transmission channel for an NSS in a TN that complies with a TN NSS isolation policy; a device for collecting isolation-related data of the TN NSS during TN NSS operation; and a device for reporting the collected isolation-related data to an isolation monitoring function at a higher layer.
[0035] In an eleventh aspect, an example embodiment of an apparatus for monitoring isolation of a network slice is provided. The apparatus for monitoring isolation of a network slice may include: a device for sending a request to a transmission control and management function of a TN to collect isolation monitoring data of an NSS; a device for receiving isolation monitoring data of the TN NSS from the transmission control and management function; a device for analyzing the isolation monitoring data during operation of the TN NSS to determine whether a slice isolation policy of the TN NSS is satisfied; and a device for reporting analysis results of the isolation monitoring data to an isolation monitoring function at a higher layer.
[0036] In a twelfth aspect, an example embodiment of an apparatus for monitoring isolation of a network slice is provided. The apparatus for monitoring isolation of a network slice may include: a device for receiving isolation monitoring information of an NSS of an NS; a device for determining whether a slice isolation policy is properly implemented during operation of the NSS based on the received isolation monitoring information; and a device for generating an alarm when it is determined that at least a portion of the slice isolation policy is not properly implemented. The received isolation monitoring information may include: an analysis result of the isolation monitoring data regarding attributes extracted from the slice isolation policy.
[0037] In a thirteenth aspect, an example embodiment of a computer-readable medium is provided. The computer-readable medium may have instructions stored thereon. When executed by at least one processor of a network function unit, the instructions cause the network function unit to: receive a slice isolation policy for an NSS in a TN domain; map the slice isolation policy to a network resource isolation policy and a service isolation policy; and map the network resource isolation policy and the service isolation policy to a network resource allocation policy and a data service forwarding policy, respectively. The network resource allocation policy and the data service forwarding policy are applied to the creation of a TN NSS.
[0038] In a fourteenth aspect, an example embodiment of a computer-readable medium is provided. The computer-readable medium may have instructions stored thereon. When executed by at least one processor of a network function unit, the instructions cause the network function unit to: create a data transmission channel for an NSS in a TN that complies with a TN NSS isolation policy; collect isolation-related data of the TN NSS during TN NSS operation; and report the collected isolation-related data to an upper-layer isolation monitoring function.
[0039] In a fifteenth aspect, an example embodiment of a computer-readable medium is provided. The computer-readable medium may have instructions stored thereon. When executed by at least one processor of a network function unit, the instructions cause the network function unit to: send a request to a transmission control and management function of a TN to collect isolation monitoring data of an NSS; receive the isolation monitoring data of the TN NSS from the transmission control and management function; during operation of the TN NSS, analyze the isolation monitoring data to determine whether a slice isolation policy of the TN NSS is satisfied; and report the analysis results of the isolation monitoring data to a higher-level isolation monitoring function.
[0040] In a sixteenth aspect, an example embodiment of a computer-readable medium is provided. The computer-readable medium may have instructions stored thereon. When executed by at least one processor of a network function unit, the instructions cause the network function unit to: receive isolation monitoring information of an NSS of an NS; determine whether a slice isolation policy is properly implemented during operation of the NSS based on the received isolation monitoring information; and generate an alarm when it is determined that at least a portion of the slice isolation policy is not properly implemented. The received isolation monitoring information includes: analysis results of isolation monitoring data for attributes extracted from the slice isolation policy.
[0041] When read in conjunction with the accompanying drawings, the accompanying drawings illustrate the principles of the exemplary embodiments of the present application; other features and advantages of the exemplary embodiments of the present application will also be apparent from the following description of the specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Some example embodiments will now be described, by way of non-limiting examples, with reference to the accompanying drawings.
[0043] Figure 1 The following illustrates the architecture of network functions for E2E network slice management that can be implemented according to some embodiments of the present application;
[0044] Figure 2 A block diagram illustrating network functionality for providing E2E slice isolation according to some example embodiments;
[0045] Figure 3 An interaction diagram illustrating network function operations for providing isolation during the NSI creation phase according to some example embodiments;
[0046] Figure 4 An interaction diagram illustrating operations of isolated network functions during a phase of NSI operation according to some example embodiments;
[0047] Figure 5 A flow chart illustrating a method for isolation of network slices according to some example embodiments;
[0048] Figure 6 A block diagram illustrating an apparatus according to some example embodiments;
[0049] Figure 7 A flow chart illustrating a method for isolation of network slices according to some example embodiments;
[0050] Figure 8 A block diagram illustrating an apparatus according to some example embodiments;
[0051] Figure 9 A flow chart illustrating a method for monitoring isolation of a network slice according to some example embodiments;
[0052] Figure 10 A block diagram illustrating an apparatus according to some example embodiments;
[0053] Figure 11 A flow chart illustrating a method for monitoring isolation of a network slice according to some example embodiments;
[0054] Figure 12 A block diagram illustrating an apparatus according to some example embodiments;
[0055] Figure 13 A block diagram illustrating network functional units according to some example embodiments is shown.
[0056] Throughout the drawings, the same or similar reference numerals designate the same or similar elements, and repeated descriptions of the same elements will be omitted. DETAILED DESCRIPTION
[0057] The following description of the present application describes in detail some exemplary embodiments with reference to the accompanying drawings. To provide a thorough understanding of the various concepts, the following description includes specific details. However, it will be apparent to those skilled in the art that these concepts can be practiced without these specific details. In some cases, well-known circuits, techniques, and components are shown in block diagram form to avoid obscuring the concepts and features described.
[0058] A network slice is a logical communication network running on a physical network; and multiple network slices running on one physical network can share network resources. Because some tenants may need to run sensitive services in a network slice that is isolated from other services to a certain extent, the difficult task of network slicing is to ensure isolation between network slices. E2E network slices span multiple parts of the network, such as the access network (AN), the transport network (TN), and the core network (CN). Transport network slices can be applied to connect the access network to the core network, and can also be applied within the core network. For example, a transport network slice can connect the access network to the user plane function (UPF) in the core network, or connect a group of user plane functions to the session management function (SMF) in the core network. E2E slice isolation needs to be ensured in the access network, transport network, and core network. This application will describe example embodiments of isolation for network slicing with reference to the transport network below; however, it should be understood that the isolation solution provided by the transport network is also applicable to the access network and the core network.
[0059] Figure 1 The structure of a network function for network slice management that can be implemented according to some embodiments of the present application is shown. Figure 1, a network slice consumer portal 110 is provided for the tenant to control and manage the E2E network slice. For example, the network slice consumer portal 110 can receive a request to create an E2E network slice from the tenant, as well as a service level agreement (SLA) or service profile, which specifies the requirements of the service to be run on the network slice, such as bandwidth, rate, latency, connectivity, mobility, etc. If the SLA is received, it can be converted into a service profile. The network slice consumer portal 110 can forward the request to create the slice and the service profile to the network slice management function (NSMF) 120 for creating the slice. For example, the tenant can also monitor and reconfigure the network slice through the network slice consumer portal 110.
[0060] When the NSMF 120 receives a request to create a network slice and a service profile, it may create a network slice instance (NSI) according to the service profile. For example, the NSMF 120 may map the service profile to a slice profile, and establish a network resource model (NRM) for the slice. The NSMF 120 may further decompose the slice profile into domain slice profiles, and based on each domain slice profile, call the domain management function to create a domain NSS. For example, the NSMF 120 may call the AN Network Slice Subnet Management Function (NSSMF) 140 to create an NSS instance in the AN domain, call the TN NSSMF 130 to create an NSS instance in the TN domain, and call the CN NSSMF 150 to create an NSS instance in the CN domain. It should be understood that the NSMF 120 may include multiple functions or sub-functions to create and manage network slice instances. For example, the NSMF 120 may include an NS coordination function, an NS security function, an NS resource model function, an NS instance function, and the like. The functions or sub-functions of NSMF 120 can be deployed as respective standalone network functions or deployed together on the same host device. It should also be understood that the domain NSSMFs 130, 140, 150 may include multiple functions or sub-functions to create and manage network slice subnet instances in their own domains. For example, each of the domain NSSMFs 130, 140, 150 may include an NSS coordination function, an NSS security function, an NSSS resource model function, and an NSS instance function, etc. The functions or sub-functions of the domain NSSMFs 130, 140, 150 can be deployed as respective standalone network functions or deployed together on the same host device. The network function or sub-function is also referred to as a network function unit, which can be implemented by using hardware or running software on hardware, or can be implemented in the form of a virtual function on a general hardware platform.
[0061] The industry has recognized that isolation is a key requirement for E2E network slicing. Isolation refers to the degree of resource sharing a tenant can tolerate, and tenants can require different levels of isolation. For example, some tenants may not mind sharing network resources with other tenants, while others may want dedicated physical or logical resources for all or specific types of service data. Below, example embodiments of methods and apparatus for supporting isolation in network slicing are discussed. In some example embodiments, fine-grained isolation policies are supported by E2E network slicing, allowing network slicing to meet tenants' diverse isolation requirements.
[0062] Figure 2 A block diagram illustrating network functionality for providing E2E slice isolation according to some example embodiments. Figure 2 In, with Figure 1 The same or similar network functions shown in FIG. 1 are denoted by the same reference numerals, and repeated descriptions thereof are omitted in this application.
[0063] refer to Figure 2 , the NSMF 120 may include an isolation management function 122 and an isolation monitoring function 124. The isolation management function 122 and the isolation monitoring function 124 may each be deployed as an independent network function, or deployed together with other NSMFs, such as but not limited to the NS coordination function of the same host device. The isolation management function 122 may be configured to establish a slice isolation policy for the network slice and, based on the slice isolation policy, assist the NSMF 120 in creating a network slice instance (NSI). The isolation monitoring function 124 may be configured to monitor whether the slice isolation policy is properly implemented in the network slice instance. The operations of the isolation management function 122 and the isolation monitoring function 124 will be discussed in detail later.
[0064] The TN NSSMF 130 may include a TN isolation control function 132 and a TN isolation monitoring function 134. Each of the TN isolation control function 132 and the TN isolation monitoring function 134 may be deployed as a standalone network function, or deployed together with other NSSMFs, such as but not limited to the NSS coordination function of the same host device. The TN isolation control function 132 may be configured to: establish an isolation policy for the network slice subnet in the TN domain; and assist the TN NSSMF 130 in creating the network slice subnet (NSS) 190 based on the isolation policy. The TN isolation monitoring function 134 may be configured to: collect isolation monitoring data related to the TN NSS 190, analyze the isolation monitoring data, and report the analysis results to a higher-level isolation monitoring function (e.g., the isolation monitoring function 124). The operations of the TN isolation control function 132 and the TN isolation monitoring function 134 will be discussed in detail later.
[0065] Although Figure 2 Although not shown, domain isolation control function 132 and domain isolation monitoring function 134 may also be applied to the access network domain and the core network domain. For example, with the assistance of the AN isolation control function, AN NSSMF 140 may create ANNSS 170; and the AN isolation monitoring function may be configured to monitor the isolation of AN NSS 170. With the assistance of the CN isolation control function, CN NSSMF 150 may create CN NSS 180; and the CN isolation monitoring function may be configured to monitor the isolation of CN NSS 180.
[0066] A transmission control and management function 160 is provided to report the status of data transmission channels to the TN isolation control function 132; the transmission control and management function 160 may include, for example, a software-defined network (SDN) controller, a network controller, or an SDN coordinator. In some embodiments, the transmission control and management function 160 may periodically and proactively report the status of activated data transmission channels to the TN isolation control function 132, or in some embodiments, the transmission control and management function 160 may report the status of activated data transmission channels to the TN isolation control function 132 in response to a request from the TN isolation control function 132 for the status of activated data transmission channels. The TN isolation control function 132 may select one or more reported data transmission channels that comply with the isolation policy of the TN NSS 190 and notify the TN NSSMF 130 of the selected one or more data transmission channels. In some embodiments, the request from the TN isolation control function 132 for the status of activated data transmission channels may include the isolation policy of the TN NSS, and the transmission control and management function 160 may only report the status of activated data transmission channels that comply with the TN NSS isolation policy to the TN isolation control function 132. In this case, the TN Isolation Control Function 132 may forward all reported active data transmission channels to the TN NSSMF 130. Further considering, for example, QoS requirements, security requirements, latency requirements, and bandwidth requirements, the TN NSSMF 130 may determine the data transmission channels (ports or VLAN IDs) for the TN NSS 190. If necessary, in response to a request from the TN NSSMF 130, the Transport Control and Management Function 160 may create new data transmission channels in the transport network for the TN NSS 190 that meet the isolation policy, QoS requirements, security requirements, latency requirements, and bandwidth requirements. The Transport Control and Management Function 160 has the ability to create, for example, dedicated data transmission channels by allocating dedicated physical / virtual routers, dedicated physical / virtual switches, and dedicated physical / virtual circuits. The Transport Control and Management Function 160 may also be configured to collect isolation data related to the TN NSS 190 in the transport network and report this data to higher-level isolation monitoring functions, such as the TN Isolation Monitoring Function 134. The operation of the Transport Control and Management Function 160 will be discussed in detail later.
[0067] TN NSS 190 connects AN NSS 170 at application endpoint 172 and CN NSS 180 at application endpoint 182. TN NSS 190 may include allocated network resources, such as routers (such as routers 1-6), switches, ports, VLAN_IDs, etc., for transmission of service data between AN NSS 170 and CN NSS 180. The allocated network resources may span multiple resource management domains. For example, Figure 2 As shown, routers 1, 2, and 5 may be in one resource management domain; and routers 3, 4, and 6 may be in another resource management domain.
[0068] exist Figure 2 In the illustrated architecture, isolation management / control and monitoring functions are provided at both the NS and NSS layers. This allows for support of fine-grained isolation policies within E2E network slices. Tenants can monitor the implementation of isolation policies and, if necessary, update network slices to correctly meet isolation requirements. Support for fine-grained isolation policies is described in detail below.
[0069] Figure 3 An interaction diagram is shown for providing isolated network function operations during the NSI creation phase according to some example embodiments. For better understanding, Figure 3 The following description of the interactions shown in can also be read in reference Figure 2 .although Figure 3 Interactions related to network functions in the TN domain are shown, but it should be understood that similar interactions can also apply to network functions in the AN and CN domains.
[0070] When the NSMF 120 receives a request to create a slice and a service profile from the network slice consumer portal 110, the isolation management function 122 of the NS layer obtains 210 a slice isolation policy from the service profile. For example, the isolation management function 122 may identify or recognize the isolation requirements included in the service profile to obtain or acquire a slice isolation policy, and the acquired slice isolation policy may be included in the slice profile of the slice to be created. The slice isolation policy is described at an abstract level and may be understood and configured by the network slice consumer. The slice isolation policy defined in the E2E slice level applies to all domains, including AN, CN, and TN domains. For example, the slice isolation policy may be "physically isolate the network functions (NFs) of the slice from other slices and the connections between NFs", or "logically isolate the network functions (NFs) of the slice from other slices and the connections between NFs", or "no isolation", etc. Physical isolation means that the network slice including the connections between NFs should be physically isolated from other slices, including, for example, process and thread isolation, physical memory / storage isolation, and physical network isolation. Logical isolation means that network slices, including connections between NFs, should be logically separated from other slices, including, for example, isolation of virtual network resources, isolation of virtual network functions, and isolation of virtual network links between network functions. No isolation means that network slices can share network resources with other slices.
[0071] The isolation management function 122 may further decompose 212 the slice isolation policy of the network slice into separate slice isolation policies for the AN NSS, TN NSS, and CN NSS. Although not shown, the NSMF 120 may also decompose the slice profile into separate AN NSS slice profiles, TN NSS slice profiles, and CN NSS slice profiles. The AN NSS isolation policy may be included in the AN NSS slice profile; the TN NSS isolation policy may be included in the TN NSS slice profile; and the CN NSS isolation policy may be included in the CN NSS slice profile.
[0072] The isolation management function 122 may also map 214 the application type to a slice profile or an NSS slice profile. In addition to the general slice and service types (SSTs) including eMBB, uRLLC, and mMTC, the slice profile may include extended information elements (IEs) or attributes to indicate finer SSTs. For example, a slice profile may include application-level information such as utilities (e.g., gas, water, and electricity), gaming, finance, autonomous driving, etc. The isolation management function 122 may then map the application type to a slice profile or an NSS slice profile. This will facilitate supporting fine-grained isolation policies, such as utility (e.g., gas, water, and electricity) data being grouped and forwarded together, gaming data being prohibited from being forwarded together with financial data, etc.
[0073] When NSMF 120 calls NSSFM to create NSS instances in various domains, the NSS slice profile containing the NSS isolation policy is also sent to the corresponding NSSFM. Figure 3 The operations in the TN domain (including the TN NSSMF 130, the TN isolation control function 132, and the transmission control and management function 160) are discussed, and the operations in the AN domain (including the operations of the AN NSSMF 140) and the CN domain (including the operations of the CN NSSMF 150) are not described in detail. It should be understood that operations similar to those in the TN domain can also be performed in the AN domain and the CN domain.
[0074] Continue to refer Figure 3 The TN isolation control function 132 of the NSS layer may receive 216 the TN NSS isolation policy from the isolation management function 122 of the NS layer, map 218 the TN NSS isolation policy to a network resource isolation policy and a service isolation policy, and further map 220 the network resource isolation policy and the service isolation policy to a network resource allocation policy and a data service forwarding policy, respectively. An example of the mapping is shown in Table 1 below.
[0075] Table 1: Mapping between data forwarding policies and slice isolation policies
[0076]
[0077]
[0078] The TN NSS isolation policy received from the isolation management function 122 may include high-level isolation requirements for the TN NSS. For example, it may specify only the isolation levels defined by the Global System for Mobile Communications (GSMA), such as physical isolation, logical isolation, or no isolation. At operation 218, taking into account the extended attributes in the TN NSS slice profile, the TN NSS isolation policy may be mapped to a fine-grained slice isolation policy containing a network resource isolation policy and a service isolation policy. The network resource isolation policy and the service isolation policy are TN domain-specific policies and are independent of TN technology. They are derived from the slice isolation policy in the TN domain and will be converted into a network resource allocation policy and a data service forwarding policy, which will be discussed later. The network resource isolation policy can be used to guide the transport control and management function 160 (e.g., an SDN controller, SDN coordinator, or network controller) to deploy and isolate transport equipment; and the relevant policies may include, for example, no isolation, physical network function isolation, logical network function isolation, physical network link isolation, logical / virtual network link isolation, etc. The service isolation policy can be used to guide the transmission control and management function 160 to configure the transmission equipment to achieve service separation / isolation; and the relevant policies may include, for example, no isolation, service type isolation, data type isolation, video type isolation, security protection level isolation, etc.
[0079] Examples of network resource isolation policies and service isolation policies are shown in Table 1 above. Referring to Table 1, network resource isolation policies include attributes such as no isolation, physical network function isolation, logical network function isolation, physical network link isolation, and logical network function isolation. Service isolation policies also include attributes such as no isolation, service type isolation, data type isolation, video type isolation, and security protection level isolation (e.g., medium isolation with data origin authentication and high isolation with integrity and confidentiality protection). For example, based on the security requirements specified in the TN NSS slice profile, the TN NSS isolation policy can be mapped to one of the following service isolation policies: no isolation, service type isolation, data type isolation, video type isolation, service type isolation, data type isolation, video type isolation, or security protection level isolation (e.g., medium isolation with data origin authentication and high isolation with integrity and confidentiality protection). Data transmission isolation rules can be determined based on the data type. For example, banking service data and financial service data can be grouped and transmitted using the same VLAN ID, while gaming service data should not be transmitted using the same VLAN ID. Depending on the service type, isolation of uRLLC data, isolation of eMBB data, isolation of mMTC data, or no isolation can be applied to the service isolation policy. Based on the video type, isolation of real-time interactive video conference data, isolation of broadcast video data or isolation of multimedia streaming data on demand can be applied to the service isolation policy. It should be understood that different or more attributes can be used in defining network resource isolation policy and service isolation policy.
[0080] In operation 220, the network resource isolation policy is mapped to the network resource allocation policy, and the service isolation policy is mapped to the data service forwarding policy. The network resource allocation policy and the data service forwarding policy are policies specific to the TN, especially for IP networks. These policies should be interpreted by the transport control and management functions (including, for example, an SDN coordinator, an SDN controller, or a network controller) and ultimately used to allocate and configure network devices. For example, the network resource allocation policy may include: standard / undifferentiated isolation; dedicated hardware for transport network resources (such as routers, switches, and channels); dedicated software for transport network resources (such as routers, switches, and channels); logically isolated virtual transport network resources such as routers, switches, and channels, etc. The data service forwarding policy may include, for example: standard / undifferentiated isolation, IPSec related rules, access control / filtering rules, DSCP (Differentiated Services Code Point) rules, forwarding rules in the flow table, etc. IPsec rules may include, for example: no IPsec, IPsec Authentication Header (AH), and IPsec Encapsulating Security Payload (ESP). AH and ESP are two protocols defined by the IETF. The AH protocol provides a mechanism for authentication only; and the ESP protocol provides data confidentiality and data authentication (integrity, source authentication, and replay protection). Filtering rules may include, for example, access control lists (ACLs) - whitelists, and ACLs - blacklists. For example, data from VLAN IDs in the ACL whitelist will be forwarded, while data from VLAN IDs in the ACL blacklist will be discarded. IETF RFC 4594 defines DSCP rules (Differentiated Services Code Points) to identify the priority of service data. As shown in Table 1, data types, service types, and video types can be mapped to corresponding DSCP classes. Although not shown in Table 1, the forwarding rules in the flow table can define the data service forwarding rules in the OpenFlow logical switch. The flow table can contain a set of flow items, including fields such as match fields, priorities, counters, and instructions. Based on service type isolation, for example, uRLLC applications with low latency and high reliability can be classified as high-priority flow items in the flow table, while mMTC applications can be classified as low-priority flow items in the flow table. It should be understood that the above-mentioned data service forwarding rules are described as examples, and different or additional rules may also be defined and applied as data service forwarding policies.
[0081] It should be understood that through the two-level mapping in operations 218 and 220, a fine-grained isolation policy is established for the TN domain; and corresponding network resource allocation requirements and data service forwarding requirements are determined for the TN domain. By applying the network resource allocation requirements and data service forwarding requirements to create TN NSS 190, fine-grained isolation is well supported in TN NSS 190.
[0082] Continue to refer Figure 3TN isolation control function 132 may receive 222 resource status, such as data transmission channels represented by ports or VLAN IDs in the transport network, from transport control and management function 160 and, based on the status of the data transmission channels, determine 224 data transmission channels that comply with the network resource allocation policy and the data traffic forwarding policy. The determined data transmission channels may be notified 226 to TN NSSMF 130 to create TN NSS 190. In some embodiments, transport control and management function 160 may periodically and proactively report the status of the activated data transmission channels to TN isolation control function 132, or in some embodiments, transport control and management function 160 may report the status of the activated data transmission channels to TN isolation control function 132 in response to a request from TN isolation control function 132 for the status of the activated data transmission channels. TN isolation control function 132 may select one or more of the reported data transmission channels that comply with the network resource allocation policy and the data traffic forwarding policy of TN NSS 190 and notify TN NSSMF 130 of the selected one or more data transmission channels. In some embodiments, the request for the status of the activated data transmission channels from the TN isolation control function 132 may further include: a network resource allocation policy and a data traffic forwarding policy for the TN NSS 190; and the transmission control and management function 160 may report only the network resource allocation policy and data traffic forwarding policy that comply with the TN NSS 190 to the TN isolation control function 132. In this case, the TN isolation control function 132 may select all reported activated data transmission channels and forward them to the TN NSSMF 130. The TN isolation control function 132 may then assist 228 the TN NSSMF 130 in creating the TN NSS 190 according to the network resource isolation policy and the traffic isolation policy. The TN NSS 190 may have a single network slice selection assistance information (S-NSSAI) to uniquely identify the network slice. In operation 228, TN NSSMF 130 may further determine a data transmission channel for TN NSS 190, represented by a port or VLAN ID, and map TN NSS 190 (e.g., S-NSSAI) to the port or VLAN ID, taking into account factors such as QoS requirements, security requirements, latency requirements, bandwidth requirements, and other factors. If one or more data transmission channels reported from TN isolation control function 132 also meet, for example, QoS requirements, security requirements, latency requirements, bandwidth requirements, and / or other requirements of TN NSS 190, TN NSSMF 130 may select and reuse at least one data transmission channel from the one or more data transmission channels reported by TN isolation control function 132, and map TN NSS 190 to the selected / reused data transmission channel.If none of the data transmission channels reported from the TN isolation control function 132 meets the QoS requirements, security requirements, latency requirements, bandwidth requirements, and other requirements of the TN NSS 190, the TN NSSMF 130 may send a request to create a data transmission channel along with the isolation policy (including the network resource allocation policy and the data service forwarding policy), QoS requirements, security requirements, latency requirements, bandwidth requirements, etc. to the transport control and management function 160. The transport control and management function 160 may then create 236 a new data transmission channel for the TN NSS 190 that meets the isolation policy, QoS requirements, security requirements, latency requirements, and bandwidth requirements. For example, when a tenant requests the creation of an E2E network slice with physical or logical isolation, the transport control and management function 160 will create a dedicated data transmission channel with an assigned dedicated physical or virtual router, a dedicated physical or virtual switch, and a dedicated physical or virtual link. The TN NSSMF 130 may map the TN NSS 190 to the created data transmission channel. The TN isolation control function 132 may also assist the TN NSSMF 130 in managing the mapping between S-NSSAI and port / VLAN IDs and the attributes shown in Table 1 above.
[0083] In some embodiments, the TN isolation control function 132 may verify 230 whether the TN slice isolation policy (including the network resource isolation policy and the service isolation policy) of the TN NSS 190 conflicts with other network slices or network slice subnets that share the same isolation policy. If so, the TN isolation control function 132 may update 232 the TN NSS 190 with a new resource allocation policy and / or data service forwarding policy to eliminate the conflict. For example, an existing slice for banking services is mapped to VLAN ID x, and a new slice for gaming services decides to reuse the slice isolation used for the existing slice, but VLAN ID x does not allow simultaneous transmission of banking data and gaming data. The TN isolation control function 132 may then select or create a new VLAN ID for the new slice.
[0084] The TN NSSMF 130 may send 234 the mapping between the TN NSS 190 and the data transmission channel to the transmission control and management function 160. The transmission control and management function 160 may configure the edge router according to the mapping relationship between the TN NSS and the data transmission channel to prevent data of other slices from being transmitted through the dedicated physical or virtual data transmission channel allocated to the TN NSS 190.
[0085] Some examples of TN NSS with corresponding isolation strategies are described here.
[0086] Example 1
[0087] uRLLC NS consumer C1 requests the creation of a network slice with physical isolation. Therefore, S-NSSAI-1 is created for this NS consumer. For the TN NSS domain, TN-NSS-1 is created by allocating dedicated hardware routers, switches, and physical circuits. Incoming data corresponding to S-NSSAI-1 is transmitted via Port_1 / Device_1 of TN-NSS-1, ensuring low-latency data transmission, data origin authentication, data integrity protection, and confidentiality protection.
[0088] Example 2
[0089] eMBB NS consumer C2 requests the creation of a network slice with logical isolation. An S-NSSAI-2 is created for this NS consumer. For the TN NSS domain, a TN-NSSI-2 is created by allocating dedicated software routers, switches, and virtual data transmission channels. Incoming data from the S-NSSAI-2 is transmitted via VLAN_ID-2 of the TN-NSS-2, which features high-throughput data transmission and data origin authentication. VLAN_ID-2 of the TN-NSS-2 channel is configured to transmit financial data, but gaming data, for example, is prohibited from being transmitted via VLAN_ID-2.
[0090] Example 3
[0091] The mMTC NS consumer C3 requests the creation of a network slice without isolation requirements. An S-NSSAI-3 is created for this NS consumer. For the TN NSS domain, standard network resources (e.g., standard routers, standard switches, and standard data transmission channels) can be allocated to create the TN-NSS-3. Incoming data corresponding to the S-NSSAI-3 will be transmitted via VLAN_ID-3 of the TN-NSS-3 using a standard data transmission policy.
[0092] Example 4
[0093] Gaming service provider NS consumer C4 requests the creation of a network slice with logical isolation. Assume that TN-NSS-1, TN-NSS-2, and TN-NSS-3 have already been created. NSMF 120 decomposes this request and calls the AN / TN / CN NSS management functions individually to create the network slice subnets. NSMF 120 also decomposes the E2E network slice isolation policy to separate the slice isolation policies for each NSS.
[0094] The TN isolation control function 132 of the TN NSS domain receives the TN NSS isolation policy and further decomposes it into a network resource isolation policy and a service isolation policy. The TN isolation control function 132 also maps the network resource isolation policy and the service isolation policy to a network resource allocation policy and a data service forwarding policy, respectively. For example, the following network resource allocation policy is obtained: dedicated software router, dedicated software switch, dedicated virtual channel; and the following data service forwarding policy is obtained: high throughput data, real-time interactive video conferencing data, no data integrity / confidentiality, no data origin authentication.
[0095] Assume that the requested gaming service provider's network slice identifier is S-NSSAI_30. TN NSSMF 130, with the assistance of TN Isolation Control Function 132, decides to reuse TN-NSS-2 based on the obtained network resource isolation policy. However, VLAN_ID-2 of TN-NSS-2 is configured to prohibit gaming data and cannot be reused to transmit S-NSSAI_30 data. Therefore, VLAN_ID-8 of TN-NSS-2 is created and used to transmit S-NSSAI_30 data.
[0096] With the assistance of the TN isolation control function 132, the TN NSSMF 130 and / or the transmission control and management function 160 configure the data transmission channel according to the obtained network resource allocation policy and data service forwarding policy, that is, the incoming data of S-NSSAI_30 will be transmitted through VLAN_ID-8 of TN-NSS-2.
[0097] Table 2 shows the mapping between the S-NSSAI and port / VLAN_ID in Example 1-4.
[0098] Table 2: Mapping between S-NSSAI and port / VLAN ID
[0099]
[0100]
[0101] Figure 4 An interaction diagram is shown for monitoring the operation of isolated network functions during the NSI operation phase according to some example embodiments. Figures 2-3 Come read Figure 4 The following description of the interactions shown in . Figure 4 Interactions related to network functions in the TN domain are shown, but it should be understood that similar interactions can also apply to network functions in the AN and CN domains.
[0102] When the network slice including AN NSS 170, TN NSS 190 and CN NSS 180 is created and operated to provide services to the tenant, the tenant can monitor the operation of the network slice to check whether the slice isolation policy is implemented by the deployment in the network slice. Figure 2 The isolation monitoring functions of the NS layer and the NSS layer are shown to be correctly implemented. In some embodiments, the isolation monitoring function 124 of the NS layer can send 310 a request for collecting isolation monitoring data to the various domain isolation monitoring functions of the NSS layer, including the TN isolation monitoring function 134. In response to the request received from the isolation monitoring function 124, the TN isolation monitoring function 134 can send 312 a request for collecting isolation monitoring data to the transmission control and management function 160. In some embodiments, the TN isolation monitoring function 134 can periodically send 312 a request for collecting isolation monitoring data to the transmission control and management function 160, and operation 310 can be omitted.
[0103] In response to a request from the TN isolation monitoring function 134, the transport control and management function 160 may collect 314 isolation monitoring data from the transport network. The transport control and management function 160 may collect isolation-related data from routers, switches, ports, VLAN IDs, and channels assigned to the TN NSS 190. For example, the transport control and management function 160 may monitor whether data traffic for a particular service is transmitted via the assigned network resources, or whether the assigned network resources are further transmitting additional service data. The transport control and management function 160 may then report 316 the collected isolation monitoring data to the TN isolation monitoring function 134. In some embodiments, the TN isolation monitoring function 134 may also collect isolation-related data from the TN NSSMF 130 ( Figure 4 ) to collect quarantine monitoring data.
[0104] The TN isolation monitoring function 134 may analyze 318 the isolation monitoring data to determine whether the slice isolation policy of the TN NSS 190 is satisfied during the operation of the TN NSS 190. For example, the TN isolation monitoring function 134 may verify whether the attributes shown in Table 2 for the TN NSS are correctly implemented. The TN isolation monitoring function 134 may then report 322 the isolation monitoring information including the analysis results or together with the original isolation monitoring data to an upper-layer isolation monitoring function (e.g., the isolation monitoring function 124 of the NS layer). In some embodiments, if it is determined that the slice isolation policy of the TN NSS 190 is not satisfied, the TN isolation monitoring function 134 may trigger 320 an update of the TN NSS 190 to comply with the TN slice isolation policy. For example, if the TN isolation monitoring function 134 finds that banking service data and gaming service data are transmitted via the same VLAN ID, and the slice isolation policy of the banking service slice specifies that banking service data should be isolated from gaming service data, then the TN isolation monitoring function 134 can trigger an update of the banking service slice, and the TN isolation control function 132 can assist the TN NSSMF 130 in reconfiguring or creating a new VLAN ID for the banking service slice. In some embodiments, operation 320 can be performed at a higher layer, for example, by the isolation monitoring function 124.
[0105] It will be appreciated that, in addition to the isolation monitoring information from the TN isolation monitoring function 134, the NS isolation monitoring function 124 may also receive isolation monitoring information from the AN domain and the CN domain. During operation of the NSS, the NS isolation monitoring function 124 may then determine 324 whether the slice isolation policy is being properly implemented. As described above, the isolation monitoring information includes analysis results of the isolation monitoring data regarding fine-grained attributes, such as those shown in Table 1-2, that are extracted from the slice isolation policy by the NS isolation management function 122. Thus, example embodiments may achieve fine-grained control, management, and monitoring of the slice isolation policy.
[0106] If the NS isolation monitoring function 124 determines that the slice isolation policy is not properly implemented in the network slice, it can generate 326 an alarm to notify the tenant or network operator of the isolation violation event. In some embodiments, the NS isolation monitoring function 124 can also trigger an update of the slice to comply with the slice isolation policy.
[0107] Figure 5 A flow chart of a method 400 for isolation of a network slice according to some example embodiments is shown. The method 400 may be performed, for example, at a network function unit, such as the TN isolation control function 132.
[0108] like Figure 5As shown, the example method 400 may include: step 410, receiving a slice isolation policy of an NSS in a TN domain; step 420, mapping the slice isolation policy to a network resource isolation policy and a service isolation policy; and step 430, mapping the network resource isolation policy and the service isolation policy to a network resource allocation policy and a data service forwarding policy, respectively. The network resource allocation policy and the data service forwarding policy may be applied to the creation of a TN NSS.
[0109] The slice isolation policy of an NSS in the TN domain may be, for example, the isolation policy of TN NSS 190. During the creation of TN NSS 190, NSMF 120 or the isolation management function 122 therein may send the isolation policy of TN NSS 90 to TN NSS 130 or TN isolation control function 132. In steps 420 and 430, a two-level mapping is performed on the slice isolation policy of the TN NSS to obtain a fine-grained network resource isolation policy, service isolation policy, network resource allocation policy, and data service forwarding policy for the TN NSS, an example of which is shown in Table 1 above. The network resource allocation policy and data service forwarding policy are applied to create TN NSS 190.
[0110] In some embodiments, network resource isolation policies may include one or more of the following attributes: no isolation, physical network function isolation, logical network function isolation, physical network link isolation, logical / virtual network link isolation, etc. Service isolation policies may include one or more of the following attributes: no isolation, service type isolation, data type isolation, video type isolation, and security protection level isolation. Service type isolation may include, for example, uRLLC services, eMBB services, and mMTC services. Data type isolation may include, for example, banking data, financial data, gaming data, smart grid data, and logistics data. Video type isolation may include, for example, real-time interactive video conferencing data, broadcast video data, and multimedia streaming data on demand. Security protection level isolation may include, for example, intermediate isolation with data origin authentication and advanced isolation with integrity and confidentiality protection.
[0111] In some embodiments, method 400 may optionally include: step 440, obtaining the status of resources in the transmission network; step 450, determining the resources in the transmission network that comply with the network resource allocation policy and data service forwarding policy based on the obtained resource status in the transmission network; and step 460, notifying the NSS management function in the TN domain of the determined resources in the transmission network to create a TN NSS.
[0112] In step 440, the TN isolation control function 132 may obtain the status of the data transmission channels in the transport network from the transport control and management function 160. In step 450, based on the status of the data transmission channels, the TN isolation control function 132 may select a data transmission channel that complies with the network resource allocation policy and the data service forwarding policy. When the determined / selected data transmission channels are notified to the TN NSSMF 130, the TN NSSFM 130 may decide the data transmission channel (port / VLAN ID) to be created for the TN slice subnet, taking into further consideration, for example, security, QoS, or additional requirements. For example, if the selected data transmission channel also meets the security requirements, latency requirements, bandwidth requirements, and QoS requirements of the TN NSS to be created, the TN NSSFM 130 may map the TN NSS to at least one of the selected data transmission channels. On the other hand, if none of the selected data transmission channels meets the security requirements and QoS requirements of the TN NSS to be created, the TN NSSFM 130 may request the transmission control and management function 160 to create a new data transmission channel that meets the network resource allocation policy, data service forwarding policy, latency requirements, bandwidth requirements, security requirements, and QoS requirements, and map the TN NSS to the created data transmission channel.
[0113] In some embodiments, method 400 may optionally include: step 470, when the slice isolation policy is shared by TN NSS 190 and other network slices or NSSs, checking whether the slice isolation policy of TN NSS 190 conflicts with other network slices or NSSs; and step 480, updating TN NSS 190 with a new resource allocation policy and / or data service forwarding policy to eliminate the conflict.
[0114] Figure 6 A block diagram of a device 500 according to some example embodiments is shown. The device may be implemented, for example, in the TN isolation control function 132 to perform Figure 5 The method 400 is shown. Figure 6 The device 500 may include: a first device (or module) 510 for executing step 410 of the method 400, a second device 520 for executing step 420 of the method 400, and a third device 530 for executing step 430 of the method 400. Optionally, the device 500 may further include: a fourth device 540 for executing step 440 of the method 400, a fifth device 550 for executing step 450 of the method 400, a sixth device 560 for executing step 460 of the method 400, a seventh device 570 for executing step 470 of the method 400, and an eighth device 580 for executing step 480 of the method 400.
[0115] Figure 7 A flow chart illustrating a method 600 for isolating a network slice according to some example embodiments. The method 600 may be performed, for example, in a network function unit such as Figure 2 A transmission control and management function 160 is shown.
[0116] refer to Figure 7 The method 600 may include: step 610, creating a data transmission channel for the NSS in the TN that complies with the isolation policy of the TN NSS; step 620, collecting isolation-related data of the TN NSS during the operation of the TN NSS; and step 630, reporting the collected isolation-related data to an upper-level isolation monitoring function.
[0117] In step 610, in response to a request from the TN NSSMF 130, the transport control and management function 160 may create a data transmission channel for the TN NSS 190. For example, when none of the existing data transmission channels meets the requirements of the TN NSS 190, including, for example, isolation policy, QoS requirements, security requirements, latency requirements, and bandwidth requirements, the TN NSSMF 130 may request the transport control and management function 160 to create a new data transmission channel for the TN NSS 190. The transport control and management function 160 may create a new data transmission channel for the TN NSS 190 by allocating network resources, such as routers and switches, to the TN NSS 190. For example, a dedicated physical or logical data transmission channel for the TN NSS 190 may be created by allocating dedicated physical or logical routers, dedicated physical or logical switches, or dedicated physical and logical circuits.
[0118] In step 620, during the operation of the TN NSS 190, isolation-related data of the TN NSS 190 may be collected. For example, the isolation-related data may be collected from network resources such as routers and switches assigned to the TN NSS 190, or from devices that control or manage network resources assigned to the TN NSS 190. In step 630, the collected isolation-related data may be reported to an isolation monitoring function at a higher layer, such as the TN isolation monitoring function 134 at the NSS layer or the isolation monitoring function 124 at the NS layer.
[0119] Figure 8 A block diagram of an apparatus 700 is shown according to some example embodiments. The apparatus may be implemented, for example, in the transport control and management function 160 to perform Figure 7 The method 600 shown in FIG. Figure 8, the device 700 may include a first device (or module) 710 for performing step 610 of the method 600 , a second device 720 for performing step 620 of the method 600 , and a third device 730 for performing step 630 of the method 600 .
[0120] Figure 9 A flow chart illustrating a method 800 for monitoring isolation of a network slice according to some example embodiments is shown. For example, the method 800 may be performed in a network function unit such as the TN isolation monitoring function 134.
[0121] refer to Figure 9 , method 800 may include: step 810, sending a request to the transmission control and management function of the TN to collect isolation monitoring data of the NSS; step 820, receiving the isolation monitoring data of the TN NSS 190 from the transmission control and management function; step 830, during the operation of the TN NSS 190, analyzing the isolation monitoring data to determine whether the slice isolation policy of the TN NSS 190 is met; and, step 840, reporting the analysis results of the isolation monitoring data to the isolation monitoring function of the upper layer.
[0122] For example, during operation of the TN NSS 190, the TN isolation monitoring function 134 may send 810 a request to collect isolation monitoring data, for example, to the transport control and management function 160. The request may be sent periodically or in response to an instruction from a higher layer (e.g., the isolation monitoring function 124 of the NS layer). Then, during operation of the TN NSS 190, the TN isolation monitoring function 134 may receive 820 the isolation monitoring data of the TN NSS 190 from the transport control and management function 160 and analyze 830 the isolation monitoring data to determine whether the slice isolation policy of the TN NSS 190 is satisfied. In some embodiments, the TN isolation monitoring function 134 may also receive the isolation monitoring data of the TN NSS 190 from at least one management function of the TN NSS 190 (e.g., the TN NSSMF 130). In step 840, the analysis results of the isolation monitoring data or together with the original isolation monitoring data are reported to, for example, the isolation monitoring function 124 of the NS layer.
[0123] In some embodiments, method 800 may optionally include: step 850 of receiving isolation monitoring data from at least one management function of TN NSS 190 (e.g., TN NSSMF 130); and step 860 of triggering an update of TN NSS 190 to comply with the slice isolation policy of TN NSS 190 when it is determined in step 830 that the slice isolation policy for TN NSS 190 is not satisfied during operation of TN NSS 190. For example, TN NSS 190 may be reconfigured or allocated new resources to comply with the isolation policy.
[0124] Figure 10 A block diagram of a device 900 according to some example embodiments is shown. The device may be implemented, for example, in the TN isolation monitoring function 134 to perform Figure 9 The method 800 shown in FIG. Figure 10 The device 900 may include: a first device (or module) 910 for executing step 810 of the method 800; a second device 920 for executing step 820 of the method 800; a third device 930 for executing step 830 of the method 800; and a fourth device 940 for executing step 840 of the method 800. Optionally, the device 900 may include: a fifth device 950 for executing step 850 of the method 800; and a sixth device 960 for executing step 860 of the method 800.
[0125] Figure 11 A flow chart illustrating a method 1000 for monitoring isolation of a network slice according to some example embodiments. For example, the method 1000 may be performed in a network function unit such as Figure 2 An isolation monitoring function 124 is shown.
[0126] refer to Figure 11 , method 1000 may include: step 1010, receiving isolation monitoring information of the NSS of the NS; step 1020, determining whether the slice isolation policy is properly implemented during the operation of the NSS based on the received isolation monitoring information; and, step 1030, generating an alarm when it is determined that at least part of the slice isolation policy is not properly implemented.
[0127] For example, during operation of a network slice, isolation monitoring information for the NSS of the network slice may be received from a domain isolation monitoring function, such as the TN isolation monitoring function 134 and / or isolation monitoring functions deployed in the AN and CN domains. In some embodiments, the isolation monitoring information may be received from the domain isolation monitoring function of the NSS periodically or in response to an isolation monitoring information request sent from the isolation monitoring function 124 to the domain isolation monitoring function of the NSS. The received isolation monitoring information may include analysis results of isolation monitoring data regarding attributes of the network resource isolation policy and the service isolation policy extracted / extended from the slice isolation policy. Examples of attributes may include the attributes shown in Table 1-2 above. Optionally, the isolation monitoring information may also include raw isolation monitoring data. The isolation monitoring information received in step 1010 may include: isolation monitoring information for the NSS in the AN domain, isolation monitoring information for the NSS in the TN domain, and isolation monitoring messages for the NSS in the CN domain. In step 1020, based on the received isolation monitoring information, the isolation monitoring function 124 determines whether the slice isolation policy is properly implemented during operation of the NS / NSS. If it is determined that at least a portion of the slice isolation policy is not being properly executed, an alarm is generated in step 1030 .
[0128] Figure 12 A block diagram of a device 1100 is shown according to some example embodiments. For example, the device may be implemented in the isolation monitoring function 124 to perform Figure 11 The method 1000 is shown. Figure 12 , the device 1100 may include: a first device (or module) 1110 for performing step 1010 of the method 1000; a second device 1120 for performing step 1020 of the method 1000; and a third device 1130 for performing step 1030 of the method 1000.
[0129] Figure 13 A block diagram of a network function unit 1200 according to some example embodiments is shown. The network function unit 1200 can be implemented as any of the above-described network functions to perform operations and / or methods related to the network functions. In some embodiments, two or more network functions can be implemented together as the network function unit 1200. For example, the NS isolation management function and the NS isolation monitoring function, or the TN isolation control function and the TN isolation monitoring function can be implemented together as the network function unit 1200.
[0130] refer to Figure 13The network function unit 1200 may include: one or more processors 1210, one or more memories 1220, and one or more network interfaces 1230 interconnected via one or more buses 1240. The one or more buses 1240 may be address, data, or control buses, and may include any interconnection mechanism, such as a series of lines on a motherboard or integrated circuit, optical fibers, optical devices, or other optical communication devices. One or more network interfaces 1230 are provided to support wired and / or wireless communications with other network functions, elements, or nodes. In some embodiments, the one or more network interfaces 1230 may implement, for example, an NG interface or an Xn interface. The one or more memories 1220 may include computer program code 1222. The one or more memories 1220 and the computer program code 1222 may be configured to, when executed by the one or more processors 1210, cause the network function unit 1200 to perform the operations and / or methods described above.
[0131] The one or more processors 1210 may be of any appropriate type suitable for the local technology network and may include one or more of: a general-purpose processor, a special-purpose processor, a microprocessor, a digital signal processor (DSP), one or more processors in a processor-based multi-core processor architecture, and a special-purpose processor such as one developed based on a field programmable gate array (FPGA) and an application-specific integrated circuit (ASIC). The one or more processors 1210 may be configured to control other elements of the network functional unit and operate in cooperation with them to implement the above-mentioned processes.
[0132] The one or more memories 1220 may include at least one storage medium in various forms, such as volatile memory and / or non-volatile storage. Volatile memory may include, but is not limited to, random access memory (RAM) or cache. Non-volatile memory may include, but is not limited to, read-only memory (ROM), a hard disk, flash memory, etc. Furthermore, the one or more memories 1220 may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or equipment, or any combination thereof.
[0133] It should be understood that the blocks shown in the accompanying drawings can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more blocks can be implemented using software and / or firmware, for example, machine executable instructions stored in a storage medium. In addition to or in place of machine executable instructions, some or all of the blocks in the accompanying drawings can be implemented, at least in part, by one or more hardware logic elements. For example, but not limited to, exemplary types of hardware logic elements that can be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), etc.
[0134] Some exemplary embodiments also provide computer program code or instructions that, when executed by one or more processors, can cause a device or apparatus to perform the above-described processes. The computer program code for performing the processes of the exemplary embodiments can be written in any combination of one or more programming languages. The computer program code can be provided to one or more processors or controllers of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the computer, partially on a remote machine, or entirely on a remote machine or server.
[0135] Some exemplary embodiments also provide a computer program product implemented in a computer-readable medium including computer program code or instructions. A computer-readable medium can be any tangible medium that can contain or store a program used by or associated with an instruction execution system, device, or apparatus. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media would include an electrical connection having one or more wires, a portable computer floppy disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0136] In addition, although the operations are described in a particular order, it should not be understood that such operations are required to be performed in the particular order or sequence shown, or that all illustrated operations are required to be performed to obtain the desired result. In some cases, multitasking and parallel processing can be advantageous. Similarly, although several specific implementation details are included in the above discussion, they should not be interpreted as limiting the scope of the application, but as descriptions of features of specific embodiments. Certain features described in the context of a single embodiment can also be combined with a single embodiment to achieve. On the contrary, the various features described in the context of a single embodiment can also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0137] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example implementations of the claims.
Claims
1. A method for isolating a network slice, performed by a transport network (TN) network slice subnet management function (NSSMF) in a TN isolation control function, comprising: Receive the slice isolation policy of the Network Slice Subnet (NSS) in the TN domain from the isolation control function of the Network Slice (NS) layer; Mapping the slice isolation strategy to a network resource isolation strategy and a service isolation strategy; Mapping the network resource isolation strategy and the service isolation strategy to the network resource allocation strategy and the data service forwarding strategy respectively, wherein the network resource allocation strategy and the data service forwarding strategy are applied to the creation of a TN NSS; receiving the status of the activated data transmission channels reported from the transmission control and management function; as well as Select one or more of the reported data transmission channels that comply with the network resource allocation policy and the data service forwarding policy of the TN NSS, and notify the NSS management function in the TN domain of the selected one or more data transmission channels, so that the NSS management function in the TN domain selects at least one data transmission channel from the one or more data transmission channels, and maps the TN NSS to the at least one data transmission channel, and the mapping relationship between the TNNSS and the at least one data transmission channel is used to configure the edge router to prevent data of other slices from being transmitted through the dedicated physical or virtual data transmission channel allocated to the TN NSS.
2. The method according to claim 1, wherein The network resource isolation policy includes one or more of the following attributes: no isolation, physical network function isolation, logical network function isolation, physical network link isolation, and logical / virtual network link isolation; The service isolation strategy includes one or more of the following attributes: no isolation, service type isolation, data type isolation, video type isolation, and security protection level isolation; The network resource allocation strategy includes one or more of the following attributes: standard / undifferentiated isolation, dedicated hardware for transport network resources, dedicated software for transport network resources, and logically isolated virtual transport network resources; as well as The data service forwarding policy includes one or more of the following attributes: standard / undifferentiated isolation, rules related to Internet Protocol Security (IPsec), access control / filtering rules, differentiated services code point (DSCP) rules, and forwarding rules in a flow table.
3. The method according to claim 1, further comprising: When the slice isolation policy is shared by the TN NSS and other network slices or NSSs, checking whether the slice isolation policy of the TN NSS conflicts with other network slices or NSSs; as well as The TN NSS is updated with a new resource allocation strategy and / or data service forwarding strategy to eliminate conflicts.
4. A network function unit implemented in a transport network (TN) network slice subnet management function (NSSMF) in a TN isolation control function, comprising: at least one processor; as well as at least one memory comprising computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause the network function unit to: Receive the slice isolation policy of the Network Slice Subnet (NSS) in the TN domain from the isolation control function of the Network Slice (NS) layer; Mapping the slice isolation strategy to a network resource isolation strategy and a service isolation strategy; Mapping the network resource isolation strategy and the service isolation strategy to the network resource allocation strategy and the data service forwarding strategy respectively, wherein the network resource allocation strategy and the data service forwarding strategy are applied to the creation of a TN NSS; receiving the status of the activated data transmission channels reported from the transmission control and management function; as well as Select one or more of the reported data transmission channels that comply with the network resource allocation policy and the data service forwarding policy of the TN NSS, and notify the NSS management function in the TN domain of the selected one or more data transmission channels, so that the NSS management function in the TN domain selects at least one data transmission channel from the one or more data transmission channels, and maps the TN NSS to the at least one data transmission channel, and the mapping relationship between the TNNSS and the at least one data transmission channel is used to configure the edge router to prevent data of other slices from being transmitted through the dedicated physical or virtual data transmission channel allocated to the TN NSS. The network function unit according to claim 4 , wherein: The network resource isolation policy includes one or more of the following attributes: no isolation, physical network function isolation, logical network function isolation, physical network link isolation, and logical / virtual network link isolation; The service isolation strategy includes one or more of the following attributes: no isolation, service type isolation, data type isolation, video type isolation, and security protection level isolation; The network resource allocation strategy includes one or more of the following attributes: standard / undifferentiated isolation, dedicated hardware for transport network resources, dedicated software for transport network resources, and logically isolated virtual transport network resources; as well as The data service forwarding policy includes one or more of the following attributes: standard / undifferentiated isolation, rules related to Internet Protocol Security (IPsec), access control / filtering rules, differentiated services code point (DSCP) rules, and forwarding rules in a flow table. The network function unit according to claim 4 , wherein: The at least one memory and the computer program code are further configured to, with the at least one processor, cause the network function unit to: When the slice isolation policy is shared by the TN NSS and other network slices or NSSs, checking whether the slice isolation policy of the TN NSS conflicts with other network slices or NSSs; as well as The TN NSS is updated with a new resource allocation strategy and / or data service forwarding strategy to eliminate conflicts.
7. A computer-readable medium having instructions stored thereon, which, when executed by at least one processor of a network function unit, cause the network function unit to: Receive the slice isolation policy of the network slice subnet (NSS) in the transport network (TN) domain from the isolation control function of the network slice (NS) layer; Mapping the slice isolation strategy to a network resource isolation strategy and a service isolation strategy; as well as Mapping the network resource isolation strategy and the service isolation strategy to the network resource allocation strategy and the data service forwarding strategy respectively, wherein the network resource allocation strategy and the data service forwarding strategy are applied to the creation of a TN NSS; receiving the status of the activated data transmission channels reported from the transmission control and management function; And select one or more of the reported data transmission channels that comply with the network resource allocation policy and the data service forwarding policy of the TN NSS, and notify the selected one or more data transmission channels to the NSS management function in the TN domain, so that the NSS management function in the TN domain selects at least one data transmission channel from the one or more data transmission channels, and maps the TN NSS to the at least one data transmission channel, and the mapping relationship between the TN NSS and the at least one data transmission channel is used to configure the edge router to prevent data of other slices from being transmitted through the dedicated physical or virtual data transmission channel allocated to the TN NSS.
Citation Information
Patent Citations
System and method for policy configuration of control plane functions by management plane functions
CN109417572A
Method, device and system for acquiring network slice
CN110661636A