Intention processing method, system and device for slice service and storage medium

By parsing and translating the customer's intent regarding security requirements for sliced ​​services, and mapping it to the security capabilities and options available in the sliced ​​network, the insecurity issues caused by the gap between customer intent and network capabilities are resolved, thereby improving the security and configuration efficiency of sliced ​​services.

CN118827092BActive Publication Date: 2026-01-16CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311258000.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-26
Publication Date
2026-01-16
Estimated Expiration
2043-09-26

AI Technical Summary

Technical Problem

There is a gap between the security requirements of the customer's sliced ​​services and the security capabilities that the sliced ​​network needs to provide, resulting in insecure sliced ​​services.

Method used

A method for processing the intent of a slice service is provided. By parsing and translating the security requirement intent of the customer, mapping it to the security capabilities and options available in the slice network, determining the functional entities and their operation actions, and invoking the functional entities to perform the operation to realize the intent.

Benefits of technology

It improves the security of slicing services, resolves the security issues caused by the gap between customer intent and network capabilities, and enhances the efficiency and automation of security configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827092B_ABST
    Figure CN118827092B_ABST
Patent Text Reader

Abstract

The application discloses a kind of slice service intention processing method, system, equipment and storage medium, the method comprises: obtaining the intention of first slice service;Wherein, intention is used to indicate the security requirement information of first slice service;In the case where intention belongs to first type intention, intention is mapped to at least one slice security capability and at least one slice security capability corresponding capability option that can be provided by the slice network to which first slice service belongs;According to the intention object of intention, at least one slice security capability and at least one slice security capability corresponding capability option, determine the functional entity corresponding to intention and the operation action executed by functional entity;Wherein, operation action includes operation type and operation;Call functional entity, execute operation action, to realize intention;In this way, the slice security intention is parsed / translated.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication, and particularly relates to a slice service intention processing method and system, a slice service intention processing device and a storage medium. BACKGROUND

[0002] The security requirements of slice services are various, such as large bandwidth requirements, high reliability requirements, ultra-low latency requirements, customized network requirements, high security and strong isolation requirements. Different security requirements will result in multiple possible choices of slice services at various stages of their life cycles.

[0003] However, there is a gap between the intention of the security requirements of the slice service expressed by the customer and the security capabilities that need to be provided by the slice network, that is, many customers are not clear about what security capabilities are needed when the above intention is implemented, resulting in the problem of insecure slice services. SUMMARY

[0004] Embodiments of the present application provide a slice service intention processing method, system, device and storage medium, which realize the analysis / translation of slice security intention.

[0005] The technical solution of the present application is implemented as follows:

[0006] In a first aspect, a slice service intention processing method is provided, and the method comprises the following steps:

[0007] obtaining an intention of a first slice service; wherein the intention is used to indicate security requirement information of the first slice service;

[0008] in a case where the intention belongs to a first type of intention, mapping the intention to at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability;

[0009] determining a function entity corresponding to the intention and an operation action performed by the function entity according to an intention object of the intention, the at least one slice security capability and the ability option corresponding to the at least one slice security capability; wherein the operation action comprises an operation type and an operation;

[0010] calling the function entity to perform the operation action, so as to realize the intention.

[0011] In a second aspect, a slice service intention processing system is provided, and the system comprises:

[0012] a slice security intention management module, configured to obtain an intention of a first slice service; wherein the intention is used to indicate security requirement information of the first slice service;

[0013] The slice security management module is configured to, in a case where the intent belongs to a first type of intent, map the intent to at least one slice security capability provided by a slice network to which the first slice service belongs and a capability option corresponding to the at least one slice security capability.

[0014] The slice security management module is configured to determine, according to an intent object of the intent, the at least one slice security capability, and the capability option corresponding to the at least one slice security capability, a functional entity corresponding to the intent and an operation action performed by the functional entity, wherein the operation action includes an operation type and an operation.

[0015] The slice security management module is further configured to invoke the functional entity to perform the operation action, so as to realize the intent.

[0016] In a third aspect, an intent processing device for a slice service is provided, and the intent processing device for the slice service includes a processor, a memory, and a communication bus.

[0017] The memory is configured to store executable instructions.

[0018] The processor is configured to execute the executable instructions stored in the memory, so as to implement the steps of the intent processing method for the slice service.

[0019] In a fourth aspect, a computer readable storage medium storing executable instructions is provided, and the computer readable storage medium stores one or more programs, which can be executed by one or more processors to implement the steps of the intent processing method for the slice service.

[0020] The present application provides an intent processing method, system, device, and storage medium for a slice service, which realizes parsing / translation of a slice security intent, that is, the present application maps a slice security configuration intent to a slice security capability and an option provided by a network, so as to support correct implementation of the slice security configuration intent and optimization of underlying security implementation. Further, according to the slice security capability and the option, an execution network element and an instruction for implementing the slice security configuration intent are determined, and the execution network element is invoked to execute the instruction, so as to implement the slice security capability configuration intent. In this way, the problem of unsafe slice service caused by a gap between an intent of a security requirement of a slice service expressed by a client and a security capability provided by a slice network in the related art is solved, and the safety of the slice service is improved. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1 A schematic diagram of an intent processing system for a slice service provided by an embodiment of the present application Figure 1 ;

[0022] Figure 2 A flowchart of a slice service intention processing method provided for an embodiment of the present application is shown in FIG. 1.

[0023] Figure 3 A schematic block diagram of a mapping list provided by the present application is shown in FIG. 2.

[0024] Figure 4 A flowchart of a mapping method provided for an embodiment of the present application is shown in FIG. 3.

[0025] Figure 5 A schematic diagram of a slice service intention processing system provided for an embodiment of the present application is shown in FIG. 4. Figure 2 ;

[0026] Figure 6 A schematic structural diagram of a slice service intention processing device provided for an embodiment of the present application is shown in FIG. 5. DETAILED DESCRIPTION

[0027] In order to make the personnel in the technical field better understand the present application scheme, the technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0028] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, not to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed, or can optionally include other steps or units inherent to the process, method, product or device.

[0029] In this document, reference to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearance of the phrase in various places in the specification does not necessarily all refer to the same embodiment, nor is it necessarily mutually exclusive of other embodiments. It is explicitly and implicitly understood that the embodiments described herein are capable of combination.

[0030] Before explaining the present application, the network slice security and intention driving in the related art are described herein:

[0031] Network slice security is the prerequisite for introducing network slicing. For the network, the network is able to support, understand and execute differentiated slice security capabilities: first, the 5th generation mobile communication technology (5G) network slice provides corresponding security measures for differentiated network implementation. Second, the 5G network supports some optional security measures at the slice level. Some security measures can also provide multiple security options, and operators can also have different security resources. These may bring different levels of security guarantees or non-security performance. Table 1 is the standard slice security capabilities currently supported by the 5G network and the security dimensions they can achieve.

[0032] Security dimensions / slicing security capabilities NSSAA SIR UPDP BP ASP PPEAP PPSI Access control √ √ √ √ Authentication √ Non-repudiation Data confidentiality √ Communication security √ √ Data integrity √ Availability √ √ √ Privacy √ √ √

[0033] Table 1

[0034] As shown in Table 1, the standard slice security capabilities currently supported by 5G networks include network slice-specific authentication and authorization (NSSAA), slice isolation for the resource (SIR), user plane data protection (UPDP), boundary protection (BP), application service protection (ASP), privacy protection of the Enhanced Authentication Protocol Identity document during NSSAA (PPEAP), and privacy protection of the Single Network Slice Selection Assistance Information (PPSI). The security dimensions that can be implemented by NSSAA include access control and authentication; the security dimensions that can be implemented by SIR include access control, availability, and privacy; the security dimensions that can be implemented by UPDP include data confidentiality and data integrity; the security dimensions that can be implemented by BP include access control, communication security, and availability; the security dimensions that can be implemented by ASP include access control, communication security, and availability; the security dimensions that can be implemented by PPEAP include privacy; and the security dimensions that can be implemented by PPSI include privacy.

[0035] In the embodiments of the present application, for slice customers like vertical industries, they need security assurance measures matched with slice implementation, and may have specific security requirements for slice network from the perspective of business using slice network. Therefore, they will require operators to provide customized network slices with different security protection capabilities. Customers such as vertical industries can express their intentions in terms of security requirements, that is, what security features they want.

[0036] Regarding slice security configuration and management, the 3rd Generation Partnership Project (3GPP) currently defines a data type named ServiceProfile including attributes of network slice related requirements, which represents the mapping requirements from customers (such as enterprises) to operators: requirements from Service-Level Agreement (SLA), additional requirements related to Network Services Provider (NSP) internal business objectives and Generic Slice Template (GST) are all considered as inputs of ServiceProfile. A 5G slice management and orchestration system can trigger corresponding configuration procedures and use ServiceProfile with values to create, configure or modify Managed Object Instance (MOI) of slice instance (Network Slice). The International Telecommunication Union (ITU) enhances the security of the slice management and orchestration system defined by 3GPP, including security orchestration, security resource module, security management and security monitoring, to support the provision of customized security capabilities (for example, isolation). Currently, the defined ServiceProfile involves three security attributes (namely "N6 Protection", "SecFunc" and "NSSAA Support"). The slice security management process defined by ITU starts from processing ServiceProfile, and the slice security attributes listed in ServiceProfile are explicit security capabilities, rather than security targets / effects similar to other attributes (such as delay, jitter). Therefore, slice security configuration can be included in the intention-driven management category, which is convenient for supporting the correct configuration of slice security and optimizing underlying implementation.

[0037] Intent-driven is a method to convert intent (what to achieve) into business, network operation and related resource requirements (how to achieve) to achieve this intent, which not only reduces the burden of related parties to understand the details of implementation, but also leaves room for optimization of implementation solutions, and is an innovative technology of network automation and orchestration. The application research and standardization of intent in related technologies involve the following fields:

[0038] Intent-based networking (IBN) network management: 3GPP standalone (SA) 5 is doing intent-driven management of mobile networks TS28.312, Intent driven management services for mobile networks and TR 28.812, Telecommunication management; Study on scenarios for Intent driven management services for mobile networks define scenarios including delivery of wireless network / delivery of wireless service / delivery of edge service / ensure coverage performance / ensure radio access network (RAN) throughput performance, and define the requirements, information model and management process of these use case scenarios. Many industry organizations have also released IBN-based systems.

[0039] Intent-driven network slice management: There are some researches on intent-driven network slice management framework, method and scenario, such as the deconstruction method from slice management intent to virtual network feature (VNF) / physical network function (PNF) and topology deployment and isolation, IBN slice management for industry 4.0 scenario, etc. SA5 just started the research project (TR28.836, Study on intent-driven management for network slicing) on intent-driven network slice management.

[0040] Intent-driven network security management: such as intent-driven data protection, slice isolation based on software-defined network (SDN), etc.

[0041] Slice security configuration is also an area that can be applied to intent-driven slice management, however, the above-mentioned intent-driven network management research does not involve slice security configuration management use cases, and there is no way to translate and analyze the intent related to slice security.

[0042] Figure 1 is a schematic block diagram of a slice service intent processing system provided by the present application. As shown in the figure, the slice service intent processing system includes a slice security related intent management module, a slice security management module, and a slice security capability module. Figure 1

[0043] Among them, the customer input slice security adopts intent objects in the form of a set of intent targets. The slice security related intent management module performs intent translation and sends intent objects, slice security capabilities, and capability target options to the slice security policy generator; the slice security policy generator propagates the generated slice security policy, and the slice service intent processing system monitors the slice security intent to perform intent verification or intent correction. The slice security policy includes (entity: operation: target). When performing intent translation, based on the slice security capability and the capability target option, and the slice security capability mapping library managed by the slice service intent processing system, the mapping from the slice security type to the multi-level security dimension, and then to the multi-option slice security capability is realized.

[0044] The slice security management module can guarantee the security of the slice model and the security of the slice ServiceProfile; the network slice management function (NSMF) / network slice subnet management function (NSSMF) is a supporting network element of slice security management, and the slice security management module can manage the security resource pool. Among them, when the slice security policy generator propagates the generated slice security policy, and the slice service intent processing system monitors the slice security intent, it is necessary to obtain the fullfulment status of the slice security intent and the management instructions based on the security of the slice model based on the security resource pool management.

[0045] ​The slice A of a user equipment (UE) A and the slice B of a UE B need to be propagated in an access network (AN), a transmission network (TN) and a core network (CN). The CN includes a session management function (SMF) and a user plane function (UPF).

[0046] The security resource pool includes, but is not limited to, a distributed denial of service (DDoS) protection, a firewall, a web application firewall (WAF) and a malicious uniform resource locator (URL) / UE detection.

[0047] The slice security capability module further includes an application server and an infrastructure.

[0048] The slice security capability module includes AN security, CN security, TN security and application security. The AN security includes radio bearer (RB) resource isolation, base station infrastructure resource isolation, user plane (UP) data protection and network slice selection assistance information (NSSAI) privacy protection. The CN security includes core network element infrastructure resource isolation, access authentication, border protection and management security. The TN security includes transmission infrastructure resource isolation and transmission security protection. The application security includes application security protection and NSSAI privacy protection.

[0049] Embodiments of the present application provide a slice service intention processing method, which is applied to a slice service intention processing system as shown in Figure 1 The slice service intention processing system as shown in Figure 2 The method includes the following steps:

[0050] Step 201, obtaining an intention of a first slice service.

[0051] The intention is used to indicate security requirement information of the first slice service.

[0052] In the embodiments of the present application, the intent specifies the expectation, including the requirements, goals and constraints of a specific service or network management workflow. The intent can provide information about specific goals, or it can provide some related details. The purpose of the intent is to define and convey knowledge about the expectation to the system, so that the automated process can reason and make appropriate decisions and actions based on it.

[0053] In the embodiments of the present application, the intent is usually understandable by humans and needs to be interpreted by machines without any ambiguity. The intent focuses more on describing the "What" that needs to be achieved, rather than the "How" that should be achieved. The intent expresses the indicators that need to be achieved, rather than how to achieve these indicators. This not only relieves the user of the burden of understanding the implementation details, but also leaves room for producers to explore alternative solutions and find the best solution. The expectation expressed by the intent is independent of the underlying system implementation, technology and infrastructure.

[0054] In the embodiments of the present application, the intent can also be decomposed in multiple dimensions, so that the intent of different dimensions represents the concerns and goals of different users in the communication autonomous network. For example, it can be decomposed in the following way: business intent: represents the goals of business users. Such intent instances can be that the operator hopes that their autonomous network can achieve revenue targets while delivering the operational service contract; or that the customer expects a good user experience. Service intent: represents the goals of service users. A service should provide corresponding functional attributes and non-functional attributes. This includes goals such as connectivity, bandwidth, latency or availability. Resource intent: represents the goals of resource users, such as meeting the performance and quality targets of services by allocating resources.

[0055] In the embodiments of the present application, slicing enables operators to build multiple dedicated, virtual, isolated, on-demand customized logical networks on top of one physical network to meet the different requirements of different industry customers for network capabilities (such as latency, bandwidth, number of connections, etc.). A network slice instance is a collection of network functions and required physical / virtual resources, composed of sub-network slice instances of radio, transport and core networks.

[0056] In the embodiments of the present application, the intent of the first slice service, also referred to as the slice security configuration intent of the first slice service, is directed to the slice security configuration intent input in the communication network, and the intent processing system of the slice service can obtain the slice security configuration intent of the first slice service from the communication network.

[0057] In the embodiments of the present application, according to the definition of SA5 TS28.312 about intention, intention represents the expectation object to achieve the target; the slice security configuration intention can be presented in the form of a set of intention objects and intention targets, that is, [intention objects, intention targets].

[0058] In some embodiments, the slice security configuration intention can be written as:

[0059] [Expectation object O,

[0060] Expectation target name and target value,

[0061] ....,

[0062] Expectation target name and target value and target context].

[0063] In some embodiments, the slice security related intention is divided into several categories for the target name and target value in the intention, and accordingly, the target name and target value also have several types.

[0064] In some embodiments, the slice security configuration intention includes a first type of intention and a second type of intention. The intention target of the first type of intention includes at least one of the following: a security dimension required by a slice service and a security level corresponding to the security dimension; wherein the intention target of the first type of intention is used to indicate the target value expected to be achieved by the first type of intention. The intention target of the second type of intention includes at least one of the following: configuring a specific network element; configuring a specific security resource; a security capability corresponding to a slice service and an option corresponding to the security capability; configuring other resources; wherein the intention target of the second type of intention is used to indicate the target value expected to be achieved by the second type of intention. The intention object of the slice security configuration intention includes at least one of the following: a slice template; a slice instance; a slice network element.

[0065] It should be noted that the target of the intention is the slice security type; that is, a certain slice security type can be taken as the target of the slice security configuration intention, and the type can be a slice security level (for example, "slice with the highest / high / basic level security") or an applicable scenario (for example, "slice for public network / general industry / special industry / power grid / vehicle to everything (V2X) / game"), and therefore, a mapping table of slice security type to security capability and option or a mapping table of slice security type to (non-)security dimension level combination is needed.

[0066] It should be noted that the target of the intention is the security dimension required by the slice service and the security level corresponding to the security dimension; that is, the intention target includes (non-)security dimension and level, and the customer can determine the required security performance or security dimension as the slice security intention (such as high privacy / high integrity protection / strong access control / high availability / autonomy) by analyzing the service, for example, compared with the acquisition type service, the power grid control type service has higher requirements for the integrity protection of data transmission and stronger access control requirements for the data network. Therefore, a mapping table of (non-)security dimension and level to security capability and option is needed.

[0067] It should be noted that the target of the intention is the security capability corresponding to the slice service and the option corresponding to the security capability, that is, the intention target includes security capability and option, such as NSSAA being on, N6 protection being deployed with DDoS protection and being filtered not to internet, and the like. Therefore, a list of differentiated slice security capabilities and options supported by the network is needed.

[0068] It should be noted that the target of the intention is to configure a specific network element or configure a specific security resource, that is, the intention target includes specific network element or resource configuration, such as configuring the NSSAA switch on the SMF or configuring the N6 interface firewall to prevent data from flowing into the internet.

[0069] In some embodiments, the slice security capability configuration management is throughout the life cycle of the slice instance, and the operation of the configuration management is different in different stages, and the operation objects involved are different, and therefore, the Object in the intention depends on the stage of the slice configuration life cycle. The intention participates in all these stages through different inputs and corresponding implementations. The security intention of each stage and the corresponding intent expression mode include but are not limited to:

[0070] 1) In the preparation phase, security attributes in slice template are designed, Object is slice template, intent can be for example [slice template, privacy is highest, data integrity is between highest and lowest level..., authentication is base].

[0071] 2) In the start phase, slice with security features is instantiated, security resources are allocated, security configuration is performed, Object is slice instance or network element, intent can be for example [ServiceProfile, targets] or [slice ID, targets] or [NF, deployed with DDoS protection].

[0072] 3) In the operation phase, security capability is modified, Object is slice instance or network element, intent can be for example [slice ID, targets] or [NF, targets].

[0073] 4) In the termination phase, slice security related elements are terminated or removed, Object is slice instance or network element, intent can be for example [slice ID, access control is 0] or [NF, Fire Wall (FW) is 0].

[0074] In summary, for the obtained input slice security configuration intent, wherein Object O can be slice template, slice instance or network element, etc., target can contain one or more of the following information: slice security type, (non-)security dimension and level, security capability and option, specific network element or resource configuration, etc.

[0075] Step 202, in the case where the intent belongs to the first type of intent, the intent is mapped to at least one slice security capability that the slice network to which the first slice service belongs can provide and the capability options corresponding to the at least one slice security capability.

[0076] In the embodiments of the present application, in the case that the intent belongs to the first type of intent, the intent processing system of the slice service needs to map the intent to at least one slice security capability provided by the slice network to which the first slice service belongs and the capability options corresponding to the at least one slice security capability; and then, according to the at least one slice security capability and the capability options corresponding to the at least one slice security capability, the corresponding function entity of the intent and the operation action performed by the function entity are determined. In the case that the intent belongs to the second type of intent, the intent processing system of the slice service can directly determine the corresponding function entity of the intent and the operation action performed by the function entity according to the intent.

[0077] In the embodiments of the present application, the intent can be mapped to one slice security capability and the capability options corresponding to the one slice security capability; or the intent can be mapped to multiple slice security capabilities and the capability options corresponding to the multiple slice security capabilities.

[0078] It should be noted that the slice security capabilities provided by different slice networks are completely different or partially different.

[0079] In some embodiments, the intent processing system of the slice service converts the input slice security intent, i.e., [intent object, intent target] into [intent object, slice security capability, capability option] ([intent object, intent target]->[intent object, slice security capability, capability option]) according to the mapping list.

[0080] Step 203, determining the corresponding function entity of the intent and the operation action performed by the function entity according to the intent object of the intent, the at least one slice security capability and the capability options corresponding to the at least one slice security capability.

[0081] The operation action includes an operation type and an operation. Here, the operation type is, for example, a new slice / updated slice; and the operation is, for example, setting the slice to a certain option.

[0082] In the embodiments of the present application, the intent processing system of the slice service obtains executable instructions according to the at least one slice security capability and the capability options corresponding to the at least one slice security capability; here, the executable instructions include the related entity for implementing the intent, the operation type and the specific operation action performed by the related entity.

[0083] For example, the present application needs to give a differentiated slice security capability execution mapping list, and the executable instructions determined according to the differentiated slice security capability execution mapping list include the option, the execution entity, the optional operation action of the capability, etc.

[0084] Exemplary, with NSSAA, i.e., slice authentication and authorization capability, executable instructions determined include:

[0085] Capability Name: A unique name and an acronym assigned to each security capability. (e.g., NSSAA)

[0086] Capability Options: Multiple choices for each security capability which can be different among slices. (e.g., NSSAA.0 (off), NSSAA.1 (on))

[0087] Managed entities: Entities to perform the capabilities (e.g., AMF or UDM)

[0088] Operations for the capability options: policy / rules to perform in the managed entities (e.g., NSSAA.0 (off): configure AMF or UDM to set NSSAA not required for the given Single Network Slice Selection Assistance Information (S-NSSAI); NSSAA.1 (on): configure AMF or UDM to set NSSAA required for the given S-NSSAIs).

[0089] “Operation type”: if the intent object already exists, “update intent object” is needed, otherwise “create intent object” is needed.

[0090] “Execution entity”: if the “intent object” is a slice template or ServiceProfile, the customer slice management function (CSMF) is needed as the “execution entity” to generate / update the slice template or ServiceProfile; if the “intent object” is a slice, the NSMF is needed as the “execution entity”, or based on the mapping relationship, the “execution entity” is determined according to the “Managed entities” of the “slice security capability”.

[0091] “Operation action”: if the “intent object” is a slice template or ServiceProfile, the specified “slice security capability” related parameters are needed to be set as the target options of the capability, i.e., “capability options”, for the management system to parse and specifically execute the corresponding operation; if the “intent object” is a slice or NF, the corresponding “operations for the capability options” can be determined according to the “slice security capability + capability target options”, i.e., “operation action”, to directly execute the operation.

[0092] In summary, for the type of intent object, the entity and operation type and operation action pseudo code are as follows:

[0093] If intent object == slice template

[0094] Operation entity = CSMF.

[0095] Operation type = update / create a slice template.

[0096] Operations: value of data type “slice security capability” in slice template is set to “capability option”.

[0097] If intent object == ServiceProfile

[0098] Operation entity = CSMF.

[0099] Operation type = update / create a ServiceProfile and update / initiate a slice instance.

[0100] Operations: value of data type “slice security capability” in ServiceProfile is set to “capability option”.

[0101] If intent object == slice ID

[0102] Operation entity = NSMF or “Managed entities”.

[0103] Operation type = update / create a slice.

[0104] Operations: value of datatype“slice security capability”in ServiceProfile of the slice ID is set to“capability option”or perform“Operation for capability option”based on the“capability option”.

[0105] If intent object == NF

[0106] Operation entity = NF or security resource.

[0107] Operation type = update / create a NF.

[0108] Operation: perform“Operation for capability option”based on the“capability option”.

[0109] In some embodiments, in the case that the intent object is a slice network element, it is determined to perform the operation according to the value of the function entity. In the case that the intent object is a slice template, it is determined that the operation performed by the function entity includes modifying the value of the function name of the variable in the slice template to the value of the operation; that is, if the intent object is template, the operation content is to assign the value of the function name (capability name) of the variable in the template to the value of the operation; if the intent object is a network element, the operation content is to perform the operation according to the value of the function entity (capability entity).

[0110] Step 204, invoke the function entity to perform the operation action to realize the intent.

[0111] In the embodiments of the present application, the intent processing system of the slice service calls executable instructions to implement the intent, that is, the instructions related to the operation action are issued to the operation entity for execution, at which time the basic slice security delivery is completed.

[0112] The embodiments of the present application provide a slice service intent processing method, which comprises: obtaining an intent of a first slice service; wherein the intent is used to indicate security requirement information of the first slice service; in the case that the intent belongs to a first type of intent, mapping the intent to at least one slice security capability provided by a slice network to which the first slice service belongs and a capability option corresponding to the at least one slice security capability; determining a functional entity corresponding to the intent and an operation action performed by the functional entity according to an intent object of the intent, the at least one slice security capability and the capability option corresponding to the at least one slice security capability; wherein the operation action comprises an operation type and an operation; and calling the functional entity to execute the operation action to implement the intent. That is, the present application proposes a slice security intent analysis / translation method, that is, mapping a slice security configuration intent to a slice security capability and an option provided by a network to support correct implementation of the slice security configuration intent and optimize the underlying security implementation; further, according to the slice security capability and the option, determining an execution network element and an instruction for implementing the slice security configuration intent, and calling the execution network element to execute the instruction to implement the slice security capability configuration intent. In this way, the problem of unsafe slice service caused by the gap between the intent of the security requirement of the slice service expressed by the customer and the security capability provided by the slice network in the related art is solved, and the security of the slice service is improved.

[0113] The present application proposes a slice security intent analysis / translation method, which improves the efficiency and automation degree of slice security selection, reduces the burden of related parties who are familiar with implementation details, and leaves room for optimized implementation solutions.

[0114] It should be noted that the starting point of the mapping process of the present application depends on the type of the intent target. The mapping method provided by the present application includes a slice security type mapping method, a slice security dimension mapping method and a slice security capability mapping method. Here, the specific form of the mapping method can be a mapping list or a model with mapping capability.

[0115] Figure 3is a schematic block diagram of a mapping list provided by the present application. The mapping list includes a list of slice security capabilities, a list of slice security dimensions with levels, and a list of slice security types. Among them, the list of slice security capabilities includes capability A-option 0, 1, 2, capability B-option 0, 1, and capability C-option 0, 1. The list of slice security dimensions with levels includes security dimension M-level 1, 2, 3 and security dimension N-level 1, 2. The list of slice security types includes slice security level 1, 2, 3 and suitable service A, B, C.

[0116] Further, according to the mapping method provided by the present application, the step of mapping the intent into at least one slice security capability provided by the slice network to which the first slice service belongs and the capability option corresponding to the at least one slice security capability in step 202 can be implemented by steps A1 to A3, or by steps A4 to A5:

[0117] Step A1, in the case that the intent target of the intent is the slice security type of the slice service, according to the slice security type mapping method, the slice security type of the first slice service is mapped into a first set.

[0118] Among them, the first set includes at least one combination composed of a security dimension of the first slice service and a security level corresponding to the security dimension.

[0119] Exemplarily, the first set includes a first combination composed of security dimension 1 and a security level 1 corresponding to the security dimension 1, a second combination composed of security dimension 2 and a security level 2 corresponding to the security dimension 2, a third combination composed of security dimension 3 and a security level 3 corresponding to the security dimension 3, and a fourth combination composed of security dimension 4 and a security level 4 corresponding to the security dimension 4; the security dimension 1, the security dimension 2, the security dimension 3 and the security dimension 4 are the security dimensions of the first slice service.

[0120] Step A2, according to the slice security dimension mapping method, mapping the first set into a second set.

[0121] The second set includes at least one combination of the security capability corresponding to the first slice service and a security option corresponding to the security capability.

[0122] For example, the second set includes a first combination of security capability 1 and a security option 1 corresponding to security capability 1, a second combination of security capability 2 and a security option 2 corresponding to security capability 2, a third combination of security capability 3 and a security option 3 corresponding to security capability 3, and a fourth combination of security capability 4 and a security option 4 corresponding to security capability 4; wherein security capability 1, security capability 2, security capability 3 and security capability 4 are security capabilities of the first slice service.

[0123] Step A3, according to the slice security capability mapping method, mapping the second set into at least one slice security capability that the slice network to which the first slice service belongs can provide and at least one capability option corresponding to the slice security capability.

[0124] Figure 4 is a flowchart of a mapping method provided by the present application. As shown in Figure 4 In the case where the intent target of the intent is the slice security type of the slice service, based on the mapping method / list, the intent target of the intent is mapped from the slice security type to the slice security level dimension and then to the slice capability with option.

[0125] The slice security type mapping method in Figure 4 includes slice security levels and appropriate services corresponding to the slice security type in the list; Figure 4 The security dimension mapping method in Figure 4 includes security dimension M-level 1 and security dimension M-level 2 in the list corresponding to the slice security level dimension;

[0126] Step A4, in the case that the intent target of the intent is the security dimension required by the slice service and the security level corresponding to the security dimension, the security dimension and the security level corresponding to the security dimension of the first slice service are mapped into a second set according to a slice security dimension mapping method.

[0127] The second set includes at least one combination of a security capability corresponding to the first slice service and a security option corresponding to the security capability.

[0128] For example, the second set includes a first combination of security capability 1 and security option 1 corresponding to security capability 1, a second combination of security capability 2 and security option 2 corresponding to security capability 2, a third combination of security capability 3 and security option 3 corresponding to security capability 3, and a fourth combination of security capability 4 and security option 4 corresponding to security capability 4; wherein the security capability 1, the security capability 2, the security capability 3 and the security capability 4 are the security capabilities of the first slice service.

[0129] Step A5, according to a slice security capability mapping method, the second set is mapped into at least one slice security capability that the slice network to which the first slice service belongs can provide and at least one capability option corresponding to the at least one slice security capability.

[0130] It should be noted that in the case that the intent target of the intent is the security dimension required by the slice service and the security level corresponding to the security dimension, the slice security level dimension can be directly mapped to the slice capability with options.

[0131] In some embodiments, if the intent is a second type of intent, but the security capability and the option corresponding to the intent target of the intent are general security capability and option, then the intent processing system of the slice service needs to call a slice security capability mapping method, for example, a slice security capability mapping table, wherein the slice security capability mapping table is a slice security capability mapping table corresponding to the slice network to which the first slice service belongs, and the table includes the security capabilities supported by the slice network to which the first slice service belongs and the options corresponding to the security capabilities; that is, in the case that the intent target of the intent is the security capability corresponding to the slice service and the option corresponding to the security capability, the security capability required by the first slice service and the option of the security capability are mapped into at least one slice security capability that the slice network to which the first slice service belongs can provide and at least one capability option corresponding to the at least one slice security capability according to the slice security capability mapping table. It should be noted that the slice security capability mapping table includes at least one of the following: an execution entity; an operation action.

[0132] In some embodiments, the method provided by the embodiments of the present application includes the following contents:

[0133] Step B1, detecting a slice security state of a first slice service.

[0134] Step B2, in the case that the state characterization intention is not satisfied, revising the intention or revising the mapping method.

[0135] In the embodiments of the present application, the intention processing system of the slice service can collect and monitor the state of the slice security to check whether the intention is satisfied or violated. The intention or the slice security capability mapping model can be revised according to the reported execution result.

[0136] The present application uses various differentiated slice security capabilities to achieve specific security dimensions, and different combinations of different options of the capabilities achieve different levels of security and non-security dimensions. A group of dimensions can represent a security category of a slice, and therefore a mapping table can be constructed to achieve mapping from security capabilities with different options to different levels of (non-) security dimensions to different levels or applicable scenarios of slice security types. Based on the mapping relationship, the target of the slice security configuration intention can be decomposed into options of security capabilities supported by the 5G network, and further according to the mapping table of the slice security capability options and the operation network element-operation action, the execution network element and the instruction for executing the configuration action are obtained, so that the execution network element executes the instruction, thereby realizing the translation of the slice security capability configuration intention.

[0137] Embodiments of the present application provide an intention processing system of a slice service, which can be applied to Figure 2 The corresponding embodiment provides an intention processing method of a slice service, which refers to Figure 5 As shown in the figure, the intention processing system 5 of the slice service includes:

[0138] The slice security intention management module 501 is configured to obtain an intention of a first slice service, wherein the intention is used to indicate security requirement information of the first slice service.

[0139] The slice security management module 502 is configured to, in the case that the intention belongs to a first type of intention, map the intention to at least one slice security capability provided by a slice network to which the first slice service belongs and at least one capability option corresponding to the at least one slice security capability.

[0140] The slice security management module 502 is configured to determine a functional entity corresponding to the intention and an operation action performed by the functional entity according to an intention object of the intention, the at least one slice security capability and the at least one capability option corresponding to the at least one slice security capability, wherein the operation action includes an operation type and an operation.

[0141] The slice security management module 502 is further configured to invoke the functional entity to perform the operation action, so as to realize the intention.

[0142] In other embodiments of the present application, the slice security management module 502 is further configured to, in the case that the intent is a second type of intent, determine, according to the intent, a function entity corresponding to the intent and an operation action performed by the function entity.

[0143] In other embodiments of the present application, the intent target of the first type of intent includes at least one of: a slice security type of a slice service; a security dimension required by the slice service and a security level corresponding to the security dimension; wherein the intent target of the first type of intent is used to indicate a target value expected to be achieved by the first type of intent.

[0144] In other embodiments of the present application, the intent target of the second type of intent includes at least one of: a specific network element to be configured; a specific security resource to be configured; a security capability corresponding to the slice service and an option corresponding to the security capability; other resources; wherein the intent target of the second type of intent is used to indicate a target value expected to be achieved by the second type of intent.

[0145] In other embodiments of the present application, the intent object of the intent includes at least one of: a slice template; a slice instance; a slice network element.

[0146] In other embodiments of the present application, the slice security intent management module 501 is configured to detect a slice security state of a first slice service.

[0147] The slice security intent management module 501 is configured to, in the case that the state represents that the intent is not satisfied, correct the intent or correct a mapping method.

[0148] In other embodiments of the present application, the mapping method includes a slice security type mapping method, a slice security dimension mapping method, and a slice security capability mapping method; the slice security management module 502 is configured to, in the case that the intent target of the intent is a slice security type of a slice service, map, according to the slice security type mapping method, the slice security type of the first slice service into a first set; wherein the first set includes at least one combination formed by a security dimension of the first slice service and a security level corresponding to the security dimension; map, according to the slice security dimension mapping method, the first set into a second set; wherein the second set includes at least one combination formed by a security capability corresponding to the first slice service and a security option corresponding to the security capability; and map, according to the slice security capability mapping method, the second set into at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability.

[0149] In other embodiments of the present application, the slice security management module 502 is configured to, in the case where the intent target of the intent is a security dimension required by the slice service and a security level corresponding to the security dimension, map the security dimension required by the first slice service and the security level corresponding to the security dimension into a second set according to a slice security dimension mapping method; the second set includes at least one combination of a security capability corresponding to the first slice service and a security option corresponding to the security capability; and map the second set into at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability according to a slice security capability mapping method.

[0150] In other embodiments of the present application, the slice security management module 502 is configured to, in the case where the intent target of the intent is a security capability corresponding to the slice service and an option corresponding to the security capability, map the security capability required by the first slice service and the option of the security capability into at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability according to a slice security capability mapping method.

[0151] In other embodiments of the present application, the slice security capability mapping table includes at least one of the following: an execution entity; and an operation action.

[0152] In other embodiments of the present application, the slice security management module 502 is configured to, in the case where the intent object is a slice template, determine that the operation performed by the function entity includes modifying a value of a function name of a variable in the slice template into a value of the operation.

[0153] In other embodiments of the present application, the slice security management module 502 is configured to, in the case where the intent object is a slice network element, determine that the operation is performed according to a value of the function entity.

[0154] It should be noted that the specific implementation process of the steps performed by the processor in this embodiment can refer to the implementation process of the slice service intent processing method provided in the corresponding embodiments, which will not be described here in detail. Figure 2 The implementation process of the slice service intent processing method provided in the corresponding embodiments, which will not be described here in detail.

[0155] Embodiments of the present application provide a slice service intent processing device, which can be applied to Figure 2 In the slice service intent processing method provided in the corresponding embodiments, referring to Figure 6 The slice service intent processing device 6 in Figure 6 corresponds to the slice service intent processing system 5 in Figure 5 includes a processor 601, a memory 602, and a communication bus 603, wherein:

[0156] The communication bus 603 is used to realize the communication connection between the processor 601 and the memory 602.

[0157] The processor 601 is used to execute the information processing program stored in the memory 602, so as to realize the following steps:

[0158] Obtain the intention of the first slice service; wherein, the intention is used to indicate the security requirement information of the first slice service;

[0159] In the case that the intention belongs to the first type intention, the intention is mapped to at least one slice security capability provided by the slice network to which the first slice service belongs and the capability options corresponding to the at least one slice security capability;

[0160] According to the intention object of the intention, the at least one slice security capability and the capability options corresponding to the at least one slice security capability, the function entity corresponding to the intention and the operation action performed by the function entity are determined; wherein, the operation action includes operation type and operation;

[0161] Call the function entity to execute the operation action to realize the intention.

[0162] In other embodiments of the present application, the processor 601 is used to execute the information processing program stored in the memory 602, so as to realize the following steps:

[0163] In the case that the intention is the second type intention, according to the intention, the function entity corresponding to the intention and the operation action performed by the function entity are determined.

[0164] In other embodiments of the present application, the intention target of the first type intention includes at least one of the following: slice security type of slice service; security dimension required by slice service and security level corresponding to security dimension; wherein, the intention target of the first type intention is used to indicate the target value expected to be achieved by the first type intention.

[0165] In other embodiments of the present application, the intention target of the second type intention includes at least one of the following: configuring a specific network element; configuring specific security resource; other resource; security capability corresponding to slice service and option corresponding to security capability; wherein, the intention target of the second type intention is used to indicate the target value expected to be achieved by the second type intention.

[0166] In other embodiments of the present application, the intention object of the intention includes at least one of the following: slice template; slice instance; slice network element.

[0167] In other embodiments of the present application, the processor 601 is used to execute the information processing program stored in the memory 602, so as to realize the following steps:

[0168] Detect the slice security state of the first slice service;

[0169] In the case that the state characterization intention is not satisfied, the intention is revised or the mapping method is revised.

[0170] In other embodiments of the present application, the mapping method includes a slice security type mapping method, a slice security dimension mapping method, and a slice security capability mapping method.

[0171] In other embodiments of the present application, the processor 601 is configured to execute an information processing program stored in the memory 602 to implement the following steps:

[0172] In the case that the intention target of the intention is a slice security type of a slice service, the slice security type of the first slice service is mapped into a first set according to a slice security type mapping method; wherein the first set includes at least one combination of a security dimension of the first slice service and a security level corresponding to the security dimension;

[0173] The first set is mapped into a second set according to a slice security dimension mapping method; wherein the second set includes at least one combination of a security capability corresponding to the first slice service and a security option corresponding to the security capability;

[0174] The second set is mapped into at least one slice security capability that can be provided by a slice network to which the first slice service belongs and a capability option corresponding to the at least one slice security capability according to a slice security capability mapping method.

[0175] In other embodiments of the present application, the processor 601 is configured to execute an information processing program stored in the memory 602 to implement the following steps:

[0176] In the case that the intention target of the intention is a security dimension required by a slice service and a security level corresponding to the security dimension, the security dimension of the first slice service and the security level corresponding to the security dimension are mapped into a second set according to a slice security dimension mapping method; wherein the second set includes at least one combination of a security capability corresponding to the first slice service and a security option corresponding to the security capability;

[0177] The second set is mapped into at least one slice security capability that can be provided by a slice network to which the first slice service belongs and a capability option corresponding to the at least one slice security capability according to a slice security capability mapping method.

[0178] In other embodiments of the present application, the processor 601 is configured to execute an information processing program stored in the memory 602 to implement the following steps:

[0179] In a case where the intent target of the intent is the security capability corresponding to the slice service and the option corresponding to the security capability, the security capability required by the first slice service and the option of the security capability are mapped into at least one slice security capability and the capability option corresponding to the at least one slice security capability that can be provided by the slice network to which the first slice service belongs, according to the slice security capability mapping method.

[0180] In other embodiments of the present application, the slice security capability mapping table includes at least one of the following: an execution entity; and an operation action.

[0181] In other embodiments of the present application, the processor 601 is configured to execute an information processing program stored in the memory 602 to implement the following steps:

[0182] In a case where the intent object is a slice template, the operation performed by the function entity includes modifying the value of the function name of the variable in the slice template into the value of the operation.

[0183] In other embodiments of the present application, the processor 601 is configured to execute an information processing program stored in the memory 602 to implement the following steps:

[0184] In a case where the intent object is a slice network element, the operation is determined to be performed according to the value of the function entity.

[0185] The method provided by the embodiments of the present application can be directly embodied as a combination of software modules executed by the processor 601. The software modules can be located in a storage medium, and the storage medium is located in the memory 602. The processor 601 reads executable instructions included in the software modules in the memory 602, and combines the necessary hardware to complete the method provided by the embodiments of the present application.

[0186] As an example, the processor 601 can be an integrated circuit chip with a signal processing capability, such as a general purpose processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The general purpose processor can be a microprocessor or any conventional processor, etc.

[0187] It should be noted that the specific implementation process of the steps performed by the processor in the present embodiment can refer to the implementation process of the intent processing method of the slice service provided by the corresponding embodiments, which will not be described here in detail. Figure 2 The implementation process of the intent processing method of the slice service provided by the corresponding embodiments, which will not be described here in detail.

[0188] The embodiments of the present application provide a computer readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method provided by the embodiments of the present application. Figure 2The corresponding embodiment provides an implementation process of the intention processing method of the slice service, which will not be described here.

[0189] It should be noted that the description of the above storage medium and device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects to the method embodiments. For technical details of the storage medium and device embodiments of the present application that are not disclosed, please refer to the description of the method embodiments of the present application for understanding.

[0190] The computer storage medium / memory can be a Read Only Memory (ROM), a Programmable Read-Only Memory (PROM), an Erasable Programmable Read-Only Memory (EPROM), an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Ferromagnetic Random Access Memory (FRAM), a Flash Memory, a magnetic surface memory, an optical disc, or a Compact Disc Read-Only Memory (CD-ROM), etc. The computer storage medium / memory can also be various terminals including one or any combination of the above memories, such as a mobile phone, a computer, a tablet device, a personal digital assistant, etc.

[0191] It should be understood that the "one embodiment" or "an embodiment" or "the present embodiment" or "the foregoing embodiment" or "some embodiments" or "some implementations" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" or "the present embodiment" or "the foregoing embodiment" or "some embodiments" or "some implementations" appearing throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in various embodiments of the present application, the size of the sequence number of each process does not mean the execution order, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The above sequence number of the embodiments of the present application is only for description, not representing the advantages and disadvantages of the embodiments.

[0192] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other manners. The embodiments described above are merely exemplary, and the unit division is merely logical function division, and there can be other division manners in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling, direct coupling, or communication connection between the components can be indirect coupling or communication connection through some interfaces, and can be electrical, mechanical, or in other forms.

[0193] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; they can be located in one place, or distributed on a plurality of network units; and some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0194] In addition, each functional unit in each embodiment of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in the form of hardware, or in the form of hardware plus software functional units.

[0195] The methods disclosed in the several method embodiments provided by the present application can be combined arbitrarily without conflict, to obtain new method embodiments.

[0196] The features disclosed in the several product embodiments provided by the present application can be combined arbitrarily without conflict, to obtain new product embodiments.

[0197] The features disclosed in the several method or device embodiments provided by the present application can be combined arbitrarily without conflict, to obtain new method embodiments or device embodiments.

[0198] Those of ordinary skill in the art can understand that all or part of the steps of the above method embodiments can be completed by a program instructing related hardware, and the foregoing program can be stored in a computer readable storage medium, and when the program is executed, the steps of the method embodiments are executed; and the foregoing storage medium includes mobile storage devices, read only memory (ROM), magnetic disks or optical disks, and various media that can store program codes.

[0199] Alternatively, the above-mentioned integrated units of the present application, if realized in the form of software function modules and sold or used as independent products, can also be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the embodiments of the method of the present application. The aforementioned storage medium includes: mobile storage devices, ROM, magnetic disks or optical disks, and various media that can store program codes.

[0200] It is worth noting that the drawings in the embodiments of the present application are only for illustrating the schematic positions of various devices on the terminal device, and do not represent the real positions in the terminal device, and the real positions of various devices or various regions can be changed or offset according to the actual situation (for example, the structure of the terminal device), and the proportions of different parts in the terminal device in the drawings do not represent the real proportions.

[0201] The above is only the implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for intent processing of a slice service, characterized in that, The method comprises: obtaining an intention of a first slice service; wherein the intention is used to indicate security requirement information of the first slice service; in the case where the intention belongs to a first type of intention, mapping the intention to at least one slice security capability that can be provided by a slice network to which the first slice service belongs and a capability option corresponding to the at least one slice security capability; determining, according to an intention object of the intention, the at least one slice security capability and the capability option corresponding to the at least one slice security capability, a functional entity corresponding to the intention and an operation action performed by the functional entity; wherein the operation action comprises an operation type and an operation; calling the functional entity to perform the operation action to realize the intention.

2. The method of claim 1, wherein, Before the calling of the functional entity to perform the operation action to realize the intention, the method further comprises: in the case where the intention is a second type of intention, determining, according to the intention, a functional entity corresponding to the intention and an operation action performed by the functional entity.

3. The method of claim 1, wherein, The intention target of the first type of intention comprises at least one of the following: a slice security type of a slice service; a security dimension required by a slice service and a security level corresponding to the security dimension; wherein the intention target of the first type of intention is used to indicate a target value expected to be achieved by the first type of intention.

4. The method of claim 2, wherein, The intention target of the second type of intention comprises at least one of the following: configuring a specific network element; configuring a specific security resource; a security capability corresponding to a slice service and an option corresponding to the security capability; wherein the intention target of the second type of intention is used to indicate a target value expected to be achieved by the second type of intention.

5. The method of claim 1, wherein, The intention object of the intention comprises at least one of the following: a slice template; a slice instance; a slice network element; other resources.

6. The method of claim 1, wherein, The method further comprises: detecting a slice security state of the first slice service; in the case where the state represents that the intention is not satisfied, revising the intention or revising a mapping method.

7. The method of claim 1, wherein, The mapping method comprises a slice security type mapping method, a slice security dimension mapping method and a slice security capability mapping method; the mapping of the intention to the at least one slice security capability that can be provided by the slice network to which the first slice service belongs and the capability option corresponding to the at least one slice security capability comprises: in the case where the intention target of the intention is a slice security type of a slice service, mapping, according to the slice security type mapping method, the slice security type of the first slice service to a first set; wherein the first set comprises at least one combination formed by a security dimension of the first slice service and a security level corresponding to the security dimension; mapping, according to the slice security dimension mapping method, the first set to a second set; wherein the second set comprises at least one combination formed by a security capability corresponding to the first slice service and a security option corresponding to the security capability; According to the slice security capability mapping method, the second set is mapped to at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability.

8. The method of claim 7, wherein, The mapping of the intent to at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability includes: In a case where an intent target of the intent is a security dimension required by a slice service and a security level corresponding to the security dimension, the security dimension of the first slice service and the security level corresponding to the security dimension are mapped to a second set according to a slice security dimension mapping method; the second set includes at least one combination of a security capability corresponding to the first slice service and one security option corresponding to the security capability. According to the slice security capability mapping method, the second set is mapped to at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability.

9. The method of claim 7, wherein, The method further includes: In a case where an intent target of the intent is a security capability corresponding to a slice service and an option corresponding to the security capability, a security capability required by the first slice service and the option of the security capability are mapped to at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability according to a slice security capability mapping method.

10. The method of claim 7, wherein, The slice security capability mapping table includes at least one of the following: An execution entity; An operation action.

11. The method of claim 1, wherein, The calling of the function entity to execute the operation action to realize the intent includes: In a case where an intent object is a slice template, it is determined that the operation executed by the function entity includes modifying a value of a function name of a variable in the slice template to a value of the operation.

12. The method of claim 1, wherein, The calling of the function entity to execute the operation action to realize the intent includes: In a case where an intent object is a slice network element, it is determined that the operation is executed according to a value of the function entity.

13. An intent processing system of a slice service, characterized by, The system includes: A slice security intent management module is configured to obtain an intent of a first slice service; the intent is used to indicate security requirement information of the first slice service. A slice security management module is configured to, in a case where the intent belongs to a first type of intent, map the intent to at least one slice security capability that can be provided by a slice network to which the first slice service belongs and an ability option corresponding to the at least one slice security capability. The slice security management module is configured to determine, according to an intent object of the intent, the at least one slice security capability and the ability option corresponding to the at least one slice security capability, a function entity corresponding to the intent and an operation action executed by the function entity; the operation action includes an operation type and an operation. The slice security management module is further configured to call the function entity to execute the operation action to realize the intent.

14. An intent processing device of a slice service, characterized by, The device includes: A memory is configured to store executable instructions. A processor configured to implement the intent processing method of the slice service of any one of claims 1 to 12 when executing executable instructions stored in the memory.

15. A computer-readable storage medium, characterized in that, The computer readable storage medium stores one or more programs, which are executable by one or more processors to implement the intent processing method of the slice service of any one of claims 1 to 12.

Citation Information

Patent Citations

  • Business management method and device and storage medium

    CN109391669A

  • Resource configuration method and device

    CN109392096A