Network security isolation method based on 5G network slicing technology

By building physical network and service chain models, applying physical isolation constraints and converting them into weighted over-graph matching problems, the delay and security isolation problems of VNF deployment in network slices are solved, and resource overhead is minimized and physical isolation of high-security service chains is achieved, and real-time requirements of power and other scenarios are met.

CN120264318APending Publication Date: 2025-07-04STATE GRID HENAN INFORMATION & TELECOMM CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510491315.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

It is difficult for the prior art to reasonably deploy virtual network functions (VNFs) of network slices in servers, while meeting the needs of power grid services for delay and secure isolation.

Method used

Build a physical network and service chain model, impose physical isolation constraints, make the VNF of each service chain exclusively occupy the physical node, build an end-to-end delay model, and transform the optimization problem into a weighted hypergraph matching problem, and use a local search algorithm to iterate to generate an approximate optimal solution.

Benefits of technology

It realizes the minimization of resource overhead while meeting the needs of delay and security isolation, ensures that the physical level of high-security service chains are completely isolated from other service chains, prevents resource competition and attacks from spreading across chains, and meets the real-time requirements of power and other scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120264318A_ABST
    Figure CN120264318A_ABST
Patent Text Reader

Abstract

The invention provides a network security isolation method based on a 5G network slicing technology, and belongs to the technical field of 5G network communication, and the method comprises the following steps: constructing a physical network model and service chain model set, and defining an optimization objective function as minimum resource overhead; applying a physical isolation constraint to enable the VNF to monopolize a physical node; constructing an end-to-end time delay model, and carrying out time delay constraint; constructing a service chain deployment optimization problem on the basis of minimizing weighted resource overhead and simultaneously satisfying physical isolation and end-to-end time delay constraints; and converting the optimization problem into a weighted hypergraph matching problem, and iteratively generating an approximate optimal solution by adopting a local search algorithm. The method has the advantages that by constructing a comprehensive constraint model of time delay, joint optimization is performed on each time delay component in a deployment stage; by applying the isolation constraint, the VNF and the virtual link of the high-security service chain are forced to exclusively occupy the physical node and the link resource, and the problem that the existing logic isolation technology cannot meet the high-security service requirement is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of 5G network communication, and particularly relates to a network security isolation method based on 5G network slicing technology. Background Art

[0002] With the wide application of network function virtualization (NFV) technology, the dynamic deployment of virtual network functions (VNFs) has become the key to improving resource utilization and reducing operating costs. In the prior art, network slicing usually realizes service isolation through virtual networks or service function chains (SFCs), and meets the delay and bandwidth requirements by optimizing the physical deployment locations of VNFs and link mapping. And attempts have been made to meet service security requirements through logical isolation in fields such as electric power and industrial control.

[0003] How to reasonably deploy VNFs that make up the network slice in the server, flexibly select the physical link to control the traffic between VNFs, and at the same time meet the requirements of power grid services for delay and security isolation is the current challenge. Summary of the Invention

[0004] In view of this, in order to overcome the deficiencies of the prior art, the present invention provides a network security isolation method based on 5G network slicing technology. To solve the above technical problems, the technical solution adopted by the present invention is as follows: The method includes the following steps: constructing a physical network model and a set of service chain models; based on the physical network model and the set of service chain models, defining an optimization objective function as minimizing resource overhead; imposing a physical isolation degree constraint so that the VNFs of each service chain occupy exclusive physical nodes and do not share physical resources with other service chains; constructing an end-to-end delay model to perform constraints on propagation delay, transmission delay, queuing delay, and processing delay; constructing a service chain deployment optimization problem based on minimizing weighted resource overhead while satisfying the physical isolation degree and end-to-end delay constraints; converting the optimization problem into a weighted hypergraph matching problem, where the weight of the hypergraph edge is defined as the negative value of resource consumption, and using a local search algorithm to iteratively generate an approximate optimal solution.

[0005] Further, the method for constructing the models of the physical network and the service chain includes:

[0006] The physical network is modeled as G=(N, L), where: N={n} is the set of physical nodes, and each node n includes processing, memory, and disk resources; L={l} is the set of physical links;

[0007] The service chain is modeled as SFC i =(I, E i ), I is the set of received service chains, and each service chain i∈I includes: an ordered VNF sequence F i ={f1→f2→...→f k}; E i={e} is the set of virtual links, E i ={e fj,fj+1 |1 ≤ j < k}, e fj is the fj-th virtual link of service chain i, connecting the fj-th and the fj+1-th VNF. Each virtual link e ∈ E i has a bandwidth requirement in units of Mbps, and k represents the endpoints of virtual link e.

[0008] Furthermore, the method for constructing an optimization objective that minimizes resource overhead based on the model set includes:

[0009]

[0010] where: is the CPU overhead of node n; is the memory overhead of node n; is the storage overhead of node n; is the bandwidth resource overhead;

[0011] The total CPU overhead, memory overhead, storage overhead, and bandwidth resource overhead in the system are as follows:

[0012]

[0013] where: and are to traverse all service chains i (i ∈ I) and all VNF types f (f ∈ F) in physical node n; and are to traverse all service chains i (i ∈ I) and each virtual link e (e ∈ E i ) of each service chain in physical link l; I is the set of service chains, i ∈ I represents the i-th service chain, i.e., SFC; F is the set of virtual network function VNF types, f ∈ F represents the VNF type; is a binary variable indicating whether VNF f in service chain i is deployed on node n; is the CPU / memory / storage resource requirement of VNF type f; is the fixed basic resource overhead of node n; is a binary variable indicating whether virtual link e of service chain i is mapped to physical link l; is the bandwidth requirement of virtual link e of service chain i; hop(l) is the number of hops of physical link l, determined by the network topology.

[0014] Furthermore, the resource overhead constraint is:

[0015] CPU resource constraint: Memory resource constraint: Disk resource constraint:

[0016] Where: is the CPU core number requirement for VNF type f; is a binary variable indicating whether VNF f in service chain i is deployed on node n; is the remaining available CPU cores of node n; is the memory requirement for VNF type f, in GB; is the disk storage requirement for VNF type f, in TB;

[0017] The link bandwidth resource constraint: When the bandwidth utilization rate of physical link l is, increase the penalty weight hop(l)×1.5 based on the bandwidth overhead;

[0018] Where: is the bandwidth requirement of virtual link e of service chain i, in Mbps; is a binary variable indicating whether virtual link e of service chain i is mapped to physical link l; B l is the total bandwidth capacity of physical link l, in Mbps.

[0019] Furthermore, the method of imposing physical isolation constraints so that the VNFs of each service chain occupy physical nodes exclusively and do not share physical resources with other service chains includes:

[0020] The physical isolation constraints include:

[0021] Node-level physical isolation:

[0022] Where: is to traverse the set of all high-security-level service chains i∈I high and iterate over each high-security-level service chain; is to traverse all VNF instances f∈F of a certain service chain i i , that is, iterate over each VNF in service chain i;

[0023] Link-level physical isolation:

[0024] Where: is to traverse all non-high-security-level service chains; is to traverse all virtual links e of the current outer service chain i and check whether it is mapped to physical link l; is the set of high-security-level service chains, and when the constraint takes effect, it prohibits VNF f′ of other service chains from sharing node n with high-security service chain i;

[0025] The calculation method of the physical isolation degree index is as follows:

[0026] The constraint condition is ISO_degree≥γ, and the physical isolation degree threshold γ∈[0,1]; where: N(i) represents the set of physical nodes occupied by service chain i; γ is the preset physical isolation degree threshold; I high is a subset of high-security-level service chains; ∣N∣ is the total number of physical nodes in the entire physical network.

[0027] Furthermore, the method for constructing an end-to-end delay model and imposing constraints on propagation delay, transmission delay, queuing delay, and processing delay includes:

[0028] Decompose the end-to-end delay constraint into the following components:

[0029]

[0030] where: is the end-to-end delay; is the propagation delay; is the transmission delay; is the queuing delay; is the processing delay; D max is the set maximum allowable end-to-end delay;

[0031] Propagation delay where: d l is the length of physical link l, in km; v is the signal propagation speed; δ el ∈{0,1} indicates whether virtual link e passes through physical link l, determined by ;

[0032] Transmission delay where: B e is the data volume of virtual link e of service chain i, unit: MB; c l is the transmission rate of physical link l, unit: MB / s;

[0033] Queuing delay where: is the bandwidth utilization rate of link l; is the bandwidth demand of virtual link e of service chain i; Bl is the total bandwidth capacity of physical link l, in Mbps; is a binary variable, indicating whether virtual link e of service chain i is mapped to physical link l. It takes 1 when virtual link e of service chain i is mapped to physical link l, otherwise it takes 0; ∑ i∈IDenote the traversal of all service chains; i: the service chain number, belonging to the service chain set; I: the set of service chains that have been deployed or to be deployed in the current system; Denote the traversal of all virtual links of service chain i; e: the virtual link number of service chain i, belonging to the virtual link set Ei of this service chain; Ei: the virtual link set of service chain i;

[0034] Processing delay: Where: is the request arrival rate of VNF v; is the service rate of VNF v, where α is the VNF processing efficiency coefficient (α ∈ [0.7, 0.9]), and the stability condition λ v <μ v ; is the CPU resource requirement of VNF v; x v,n ∈ {0, 1} is a binary variable indicating whether VNF v is deployed on node n; is the remaining CPU resource amount of node n.

[0035] Furthermore, the steps of the hypergraph transformation and solution include:

[0036] Construct a weighted hypergraph model:

[0037] Map the service chain deployment problem to a weighted hypergraph g = (v, ε, W), where: each service chain i ∈ I corresponds to a hyperedge εi, and the set of physical nodes it covers is That is, the deployment nodes of all VNFs of service chain i; the node weight represents the comprehensive remaining resources of node n; the hyperedge weight is defined as the negative value of the total deployment cost of service chain i, and the negative value indicates that maximizing the weight is equivalent to minimizing the cost; where: H(ε i ) is the set of physical nodes covered by hyperedge ε i ; W n is the comprehensive remaining resource weight of node n; w(ε i ) is the hyperedge weight of service chain i, that is, the negative value of the total cost; v is the set of nodes of the hypergraph, corresponding to the physical node set N; ε is the set of hyperedges of the hypergraph, corresponding to the service chain set I;

[0038] Generate an initial feasible solution:

[0039] Randomly select a deployment plan that meets the following conditions Node-level constraints: node resource capacity, physical isolation, and mapping uniqueness; link-level constraints: bandwidth capacity and path hop count limit; if a feasible solution cannot be generated, reject the service chain request;

[0040] Neighborhood Operations and Iterative Optimization:

[0041] The local search algorithm adopts a simulated annealing strategy and performs the following operations:

[0042] VNF Node Migration: Select VNF f ∈ F of service chain i i , and migrate it from node n to n′, subject to: resource capacity physical isolation requirements For high-security service chain i ∈ I high ;

[0043] Link Path Remapping: Replace the physical path P i of virtual link e ∈ E e with a path P e ′ with fewer hops, subject to: bandwidth constraint delay constraint where: P e is the set of physical paths of virtual link e;

[0044] Weight Evaluation and Solution Update:

[0045] Calculate the weight change ΔW = W new -W old , where: W new = ∑ εi∈ε′ w(ε i ), ε′ is the set of hyperedges affected by the operation; Acceptance Criterion: If ΔW > 0, directly update the solution; otherwise accept it with probability p = e ΔW / T ; where ΔW is the weight difference between the neighborhood solution and the original solution; W new , W old are the total weights of the hyperedge subsets of the neighborhood solution and the original solution, and T is the temperature parameter;

[0046] Termination Condition Judgment:

[0047] Stop the iteration when any of the following conditions is met: the total weight has not been improved for K = 50 consecutive iterations; the cumulative calculation time ≥ T max = 1 second; all neighborhood operations cannot generate a better solution; where: T max is the maximum allowable calculation time of the algorithm, and K is the termination threshold of the local search algorithm without improvement iterations.

[0048] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the computer device implements the above network security isolation method based on 5G network slicing technology.

[0049] A computer-readable storage medium stores a computer program, characterized in that when the computer program is executed by a computer device, the above-mentioned network security isolation method based on 5G network slicing technology is implemented.

[0050] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0051] 1. By constructing a comprehensive constraint model of propagation delay, transmission delay, queuing delay, and processing delay, jointly optimizing each delay component during the deployment phase to ensure that the end-to-end delay of any service chain is always lower than a preset threshold, meeting the stringent real-time requirements of scenarios such as power.

[0052] 2. By imposing node-level and link-level physical isolation constraints, forcing the VNFs and virtual links of high-security service chains to exclusively occupy physical node and link resources, ensuring complete physical isolation from other service chains, effectively preventing resource contention and the cross-chain spread of potential attacks, and solving the problem that existing logical isolation technologies cannot meet the high-security service requirements.

[0053] 3. By transforming the service chain deployment problem into a weighted hypergraph matching model, defining the hyperedge weight with the negative value of resource consumption, and dynamically adjusting the VNF deployment location and link mapping path in combination with a local search algorithm, achieving global minimization of resource overhead while satisfying physical isolation and delay constraints.

[0054] 4. By introducing a neighborhood operation mechanism with a simulated annealing strategy, supporting flexible adjustment of node migration and link remapping, and combining weight difference evaluation and probability acceptance criteria, effectively avoiding local optimal solutions and ensuring the generation of an approximate optimal deployment plan that meets multiple constraints within limited computing time. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] The present invention will be further described in detail below with reference to the drawings.

[0056] Figure 1 : Schematic diagram of the process in the present invention; DETAILED DESCRIPTION OF THE EMBODIMENTS

[0057] To better understand the present invention, the content of the present invention will be further clearly elaborated below in conjunction with embodiments and drawings. However, the protection scope of the present invention is not limited to the following embodiments. In the following description, a large number of specific details are given to provide a more thorough understanding of the present invention. However, it is obvious to those skilled in the art that the present invention can be implemented without one or more of these details.

[0058] Embodiment 1: Refer to Figure 1 , a network security isolation method based on 5G network slicing technology in this embodiment includes the following steps:

[0059] Construct a set of physical network models and service chain models;

[0060] Based on the physical network model and the set of service chain models, define the optimization objective function as minimizing the resource overhead;

[0061] Apply the physical isolation degree constraint so that the VNFs of each service chain exclusively occupy physical nodes and do not share physical resources with other service chains;

[0062] Construct an end-to-end delay model and impose constraints on propagation delay, transmission delay, queuing delay, and processing delay;

[0063] Based on minimizing the weighted resource overhead and simultaneously satisfying the physical isolation degree and end-to-end delay constraints, construct a service chain deployment optimization problem;

[0064] Transform the optimization problem into a weighted hypergraph matching problem, where the weight of the hypergraph edge is defined as the negative value of the resource consumption, and use a local search algorithm to iteratively generate an approximate optimal solution. This solution transforms the complex security isolation problem into a multi-constraint optimization problem by establishing a two-layer model of the physical network and the service chain. The weighted hypergraph matching model effectively integrates the node resource overhead, link bandwidth consumption, and physical isolation degree indicators. The combination of the local search algorithm and the simulated annealing strategy realizes the efficient search for the approximate optimal solution while ensuring the exclusive use of resources by high-security service chains.

[0065] Refer to Figure 1 , the method for constructing the models of the physical network and the service chain includes:

[0066] Model the physical network as G=(N, L), where: N={n} is the set of physical nodes, and each node n includes processing, memory, and disk resources; L={l} is the set of physical links; the topological abstraction method of the physical network adopts the weighted graph structure in graph theory, and the node attributes cover three core resource dimensions of computing, storage, and network;

[0067] Model the service chain as SFC i =(I, E i ), I is the set of received service chains, and each service chain i∈I includes: an ordered VNF sequence F i ={f1→f2→...→f k}; E i ={e} is the set of virtual links, E i ={e fj,fj+1 ∣1≤j<k}, e fj is the jth virtual link of service chain i, connecting the fjth and the fj+1th VNF. Each virtual link e∈E i has a bandwidth requirement The unit is Mbps, and k represents the endpoints of the virtual link e. The service chain model introduces an ordered VNF sequence and virtual link association rules to ensure the logical integrity of the service function chain for service traffic. This modeling method provides a basis for mathematical computability for subsequent resource allocation.

[0068] Refer to Figure 1 , based on the physical network model and the set of service chain models, the method for constructing an optimization objective with minimized resource overhead includes:

[0069]

[0070] Where: is the CPU overhead of node n; is the memory overhead of node n; is the storage overhead of node n; is the bandwidth resource overhead;

[0071] Total resource overhead = (CPU sum + memory sum + storage sum) + bandwidth sum × number of hops, CPU sum = the CPU requirements of each VNF on all nodes are added together, and the basic overhead of the node is included; memory sum = the memory occupation of each VNF is calculated by stacking according to nodes; bandwidth sum = the bandwidth required for each virtual link × the sum of the number of hops of the physical link it maps to;

[0072] The total CPU overhead, memory overhead, storage overhead, and bandwidth resource overhead in the system are as shown in the following formula:

[0073]

[0074] Where: and are to traverse all service chains i (i ∈ I) and all VNF types f (f ∈ F) in physical node n; and are to traverse all service chains i (i ∈ I) and each virtual link e (e ∈ E i ) in physical link l; I is the set of service chains, i ∈ I represents the i-th service chain, that is, SFC; F is the set of virtual network function VNF types, f ∈ F represents the VNF type; is a binary variable indicating whether VNF f in service chain i is deployed on node n; is the CPU / memory / storage resource requirement of VNF type f; is the fixed basic resource overhead of node n; is a binary variable indicating whether the virtual link e of service chain i is mapped to physical link l; is the bandwidth requirement of the virtual link e of service chain i; hop(l) is the number of hops of physical link l, which is determined by the network topology;

[0075] The design of the objective function for minimizing resource overhead follows the principle of "weighting according to demand", using linear superposition calculation for CPU, memory, and storage resources, and introducing a hop penalty term for link overhead; this function can accurately reflect the marginal cost differences in network slice deployment and provide a quantitative basis for priority scheduling of different service chains.

[0076] See Figure 1 , the resource overhead constraint is:

[0077] CPU resource constraint: Memory resource constraint: Disk resource constraint: The node-level resource constraint uses a hard threshold limit to enforce the capacity upper limit of physical resource sharing;

[0078] Where: is the CPU core number requirement for VNF type f; is a binary variable indicating whether VNF f in service chain i is deployed on node n; is the remaining available CPU cores of node n; is the memory requirement for VNF type f, in GB; is the disk storage requirement for VNF type f, in TB;

[0079] The described link bandwidth resource constraint: When the bandwidth utilization rate of physical link l , based on the bandwidth overhead, increase the penalty weight hop(l)×1.5; the link bandwidth constraint introduces a dynamic penalty mechanism, which automatically triggers an increase in the overhead coefficient when the link utilization rate exceeds the critical value, realizing the synergistic effect of congestion warning and load balancing;

[0080] Where: is the bandwidth requirement of virtual link e of service chain i, in Mbps; is a binary variable indicating whether virtual link e of service chain i is mapped to physical link l; B l is the total bandwidth capacity of physical link l, in Mbps.

[0081] See Figure 1 , imposing physical isolation degree constraints, the methods for making the VNFs of each service chain exclusive to physical nodes and not sharing physical resources with other service chains include:

[0082] The described physical isolation constraints include:

[0083] Node-level physical isolation: On each physical node n, all VNFs f∈F of all high-security service chains i∈I high iThe total number of deployments does not exceed 1.

[0084] Among them: For traversing all high-security service chains i ∈ I high of the set, iterate over each high-security service chain; For traversing all VNF instances f ∈ F of a certain service chain i i , that is, iterate over each VNF in service chain i;

[0085] Link-level physical isolation: When the sum of the two summation results in the formula satisfies 0, it means that for any physical link l and any high-security service chain i high , all virtual links of non-high-security service chains are prohibited from being mapped to the physical link l (because is a 0-1 variable, and the sum being 0 means all are 0); force the virtual links of high-security service chains to be completely isolated from those of other service chains on the physical link and prohibit sharing;

[0086] Among them: For traversing all non-high-security service chains; For traversing all virtual links e of the current outer service chain i to check if it is mapped to the physical link l; is the set of high-security service chains. When the constraint takes effect, it prohibits the VNF f' of other service chains from sharing the node n with the high-security service chain i;

[0087] Physical isolation degree = (number of nodes occupied by high-security service chains) ÷ (total number of nodes in the physical network). Numerator: the number of physical nodes exclusively occupied by high-security service chains; Denominator: the total number of available nodes in the entire physical network; Constraint condition: this ratio must be greater than or equal to the preset threshold γ;

[0088] The calculation method of the physical isolation degree index is:

[0089] The constraint condition is ISO_degree ≥ γ, and the physical isolation degree threshold γ ∈ [0, 1]; Among them: N(i) represents the set of physical nodes occupied by service chain i; γ is the preset physical isolation degree threshold; I high is the subset of high-security service chains; ∣N∣ is the total number of physical nodes in the entire physical network; the physical isolation degree index is achieved through a dual control strategy: implementing exclusive VNF deployment for high-security service chains at the node level and implementing physical path isolation for non-secure traffic at the link level; the introduction of the isolation degree threshold γ enables the system to make a configurable trade-off between security requirements and resource efficiency.

[0090] Refer toFigure 1 The method for constructing an end-to-end delay model and imposing constraints on propagation delay, transmission delay, queuing delay, and processing delay includes:

[0091] The end-to-end delay model adopts a decomposition-based modeling method, decomposing the total delay into four independent components: propagation, transmission, queuing, and processing; total delay = signal propagation time + data transmission time + queuing waiting time + VNF processing time. Signal propagation time: is proportional to the link length and inversely proportional to the transmission medium speed; data transmission time: data volume ÷ link transmission rate; queuing time: grows non-linearly with the increase in link utilization; processing time: depends on the ratio of the computing power of the VNF to the request load. Mapping relationships are established for each component with network topology parameters, resource allocation status, and service load characteristics to provide accurate QoS prediction capabilities for delay-sensitive service chains; the end-to-end delay constraint is decomposed into the following components:

[0092]

[0093] Where: is the end-to-end delay; is the propagation delay; is the transmission delay; is the queuing delay; is the processing delay; D max is the set maximum allowable end-to-end delay;

[0094] Propagation delay Where: d l is the length of the physical link l, in km; v is the signal propagation speed, set to 2×10 5 km / s; δ el ∈{0,1} indicates whether the virtual link e passes through the physical link l, determined by ;

[0095] Transmission delay Where: B e is the data volume of the virtual link e of service chain i, in MB; c l is the transmission rate of the physical link l, in MB / s;

[0096] Queuing delay Where: is the bandwidth utilization of link l; is the bandwidth requirement of the virtual link e of service chain i; Bl is the total bandwidth capacity of the physical link l, in Mbps; is a binary variable, indicating whether the virtual link e of service chain i is mapped to the physical link l. It takes 1 when the virtual link e of service chain i is mapped to the physical link l, otherwise 0; ∑ i∈IIndicates traversing all service chains, counting the bandwidth occupancy of all service chains on the physical link l, and ensuring coverage of all possible impacts of service chains; i: service chain number, belonging to the service chain set; I: the set of service chains that have been deployed or to be deployed in the current system; Indicates traversing all virtual links of service chain i, and counting the total bandwidth demand of all virtual links of a single service chain i on the physical link l; e: virtual link number of service chain i, belonging to the virtual link set Ei of this service chain; Ei: virtual link set of service chain i;

[0097] Processing delay: Among them: Is the request arrival rate of VNF v; Is the service rate of VNF v, where α is the VNF processing efficiency coefficient (α ∈ [0.7, 0.9]), and the stability condition λ v <μ v ; Is the CPU resource demand of VNF v; x v,n ∈ {0, 1} is a binary variable indicating whether VNF v is deployed on node n; Is the remaining CPU resource amount of node n.

[0098] Refer to Figure 1 , the hypergraph matching problem solving framework includes three major innovative mechanisms: 1) The negative correlation design between hyperedge weight and resource consumption, transforming the minimization problem into a maximization weight search; 2) The neighborhood operation combination based on the annealing strategy, supporting the collaborative optimization of VNF node migration and link remapping; 3) The adaptive convergence judgment controlled by dynamic temperature parameters, balancing the global search and local development efficiency. The steps of the hypergraph transformation and solution include:

[0099] Construct a weighted hypergraph model:

[0100] Map the service chain deployment problem to a weighted hypergraph g = (v, ε, W), where: each service chain i ∈ I corresponds to a hyperedge εi, and the set of physical nodes it covers is That is, the deployment nodes of all VNFs of service chain i; the node weight Represents the comprehensive remaining resources of node n; the hyperedge weight Is defined as the negative value of the total deployment cost Of service chain i, and the negative value indicates that maximizing the weight is equivalent to minimizing the cost; among them: H(ε i ) is the set of physical nodes covered by hyperedge ε i ; W n Is the comprehensive remaining resource weight of node n; w(ε i) is the hyperedge weight of service chain i, i.e., the negative value of the total cost; v is the set of nodes in the hypergraph, corresponding to the physical nodes N; ε is the set of hyperedges in the hypergraph, corresponding to the service chain set I;

[0101] Generate an initial feasible solution:

[0102] Randomly select a deployment plan that meets the following conditions Node-level constraints: node resource capacity, physical isolation, and mapping uniqueness; link-level constraints: bandwidth capacity and path hop count limit; if a feasible solution cannot be generated, reject the service chain request;

[0103] Neighborhood operation and iterative optimization:

[0104] The local search algorithm adopts the simulated annealing strategy and performs the following operations:

[0105] VNF node migration: Select VNF f∈F of service chain i i , and migrate it from node n to n′, which needs to meet: resource capacity Physical isolation requirements For high-security service chain i∈I high ;

[0106] Link path remapping: Replace the physical path P of virtual link e∈E i with a path P e ′ with fewer hops, which needs to meet: bandwidth constraint e Delay constraint Delay constraint where: P e is the set of physical paths of virtual link e;

[0107] Weight evaluation and solution update:

[0108] Calculate the change in the weight of the hyperedge subset of the neighborhood solution ΔW = W new -W old , where: W new =∑ εi∈ε′ w(ε i ), ε′ is the set of hyperedges affected by the operation; acceptance criterion: if ΔW > 0, directly update the solution; otherwise, accept it with probability p = e ΔW / T ; where, ΔW is the weight difference between the neighborhood solution and the original solution; W new , W old are the total weights of the hyperedge subsets of the neighborhood solution and the original solution, and T is the temperature parameter;

[0109] If the new weight - the old weight > 0 → must accept; otherwise → accept according to the probability exp((new weight - old weight) / temperature); weight: a quantitative indicator reflecting the quality of the deployment plan (the larger the value, the better), temperature: a parameter controlling the exploration ability of the algorithm, which gradually decreases with the increase of the number of iterations;

[0110] Termination condition determination:

[0111] Stop iteration when any of the following conditions is met: the total weight has not been improved for K = 50 consecutive iterations; the cumulative calculation time ≥ T max = 1 second; all neighborhood operations cannot generate a better solution; where: T max is the maximum allowable calculation time of the algorithm, and K is the termination threshold of the non-improved iteration of the local search algorithm.

[0112] Beneficial effects:

[0113] 1. By imposing node-level and link-level physical isolation constraints, forcing the VNFs and virtual links of the high-security service chain to exclusively occupy physical node and link resources, ensuring complete physical isolation from other service chains, effectively preventing resource contention and the cross-chain spread of potential attacks, and solving the problem that existing logical isolation technologies cannot meet the high-security business requirements;

[0114] 2. By constructing a comprehensive constraint model of propagation delay, transmission delay, queuing delay, and processing delay, jointly optimizing each delay component during the deployment phase, ensuring that the end-to-end delay of any service chain is always lower than the preset threshold, and meeting the stringent real-time requirements of scenarios such as power;

[0115] 3. By transforming the service chain deployment problem into a weighted hypergraph matching model, defining the hyperedge weight with the negative value of resource consumption, and combining the local search algorithm to dynamically adjust the VNF deployment location and link mapping path, achieving global minimization of resource overhead under the satisfaction of physical isolation and delay constraints;

[0116] 4. By introducing a neighborhood operation mechanism with a simulated annealing strategy, supporting flexible adjustment of node migration and link remapping, and combining the weight difference evaluation and probability acceptance criterion, effectively avoiding local optimal solutions, and ensuring the generation of an approximate optimal deployment plan that meets multiple constraints within a limited calculation time.

[0117] Embodiment 2: A computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the computer device implements the method described in Embodiment 1.

[0118] Embodiment 3: A computer-readable storage medium storing a computer program, characterized in that when the computer program is executed by a computer device, it implements the method described in Embodiment 1.

[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Any other modifications or equivalent replacements made by those of ordinary skill in the art to the technical solutions of the present invention should be covered within the scope of the claims of the present invention as long as they do not depart from the spirit and scope of the technical solutions of the present invention.

Claims

1. A network security isolation method based on 5G network slicing technology, characterized in that, Including the following steps: Construct a physical network model and a set of service chain models; Based on the physical network model and the set of service chain models, define the optimization objective function as minimizing resource overhead; Apply the physical isolation degree constraint, so that the VNF of each service chain exclusively occupies a physical node and does not share physical resources with other service chains; Construct an end-to-end delay model and impose constraints on propagation delay, transmission delay, queuing delay, and processing delay; Based on minimizing the weighted resource overhead and satisfying the physical isolation degree and end-to-end delay constraints, construct a service chain deployment optimization problem; Transform the optimization problem into a weighted hypergraph matching problem, where the weight of the hypergraph edge is defined as the negative value of resource consumption, and use a local search algorithm to iteratively generate an approximate optimal solution.

2. The network security isolation method based on 5G network slicing technology according to claim 1, wherein, The method for constructing the models of the physical network and the service chain includes: Model the physical network as G=(N,L), where: N={n} is the set of physical nodes, and each node n includes processing, memory, and disk resources; L={l} is the set of physical links; The service chain is modeled as SFC i =(I, E i ), where I is the set of received service chains, and each service chain i ∈ I contains: an ordered VNF sequence F i ={f1 → f2 →... → f k}; E i ={e} is the set of virtual links, and E i ={e fj,fj+1 |1 ≤ j < k}, where e fj is the jth virtual link of service chain i, connecting the fjth and the (fj + 1)th VNF. Each virtual link e ∈ E i has a bandwidth requirement in Mbps, and k represents the endpoints of the virtual link e 3. The network security isolation method based on 5G network slicing technology according to claim 2, characterized in that, Based on the set of models, the method for constructing the optimization objective of minimizing resource overhead includes: Wherein: is the CPU overhead of node n; is the memory overhead of node n; is the storage overhead of node n; is the bandwidth resource overhead; The total CPU overhead, memory overhead, storage overhead, and bandwidth resource overhead in the system are as shown in the following formula: Wherein: and are used to traverse all service chains i (i ∈ I) and all VNF types f (f ∈ F) in the physical node n; and are used to traverse all service chains i (i ∈ I) and each virtual link e (e ∈ E i ) in the physical link l; I is the set of service chains, i ∈ I represents the i-th service chain, i.e., SFC; F is the set of virtual network function VNF types, f ∈ F represents the VNF type; is a binary variable indicating whether the VNF f in the service chain i is deployed on the node n; is the CPU / memory / storage resource requirement of the VNF type f; is the fixed basic resource overhead of the node n; is a binary variable indicating whether the virtual link e of the service chain i is mapped to the physical link l; is the bandwidth requirement of the virtual link e of the service chain i; hop(l) is the number of hops of the physical link l, which is determined by the network topology.

4. The network security isolation method based on 5G network slicing technology according to claim 3, wherein, The resource overhead constraint is: CPU resource constraint: Memory resource constraint: Disk resource constraint: Wherein: is the CPU core number requirement for VNF type f; is a binary variable indicating whether VNF f in service chain i is deployed on node n; is the remaining available CPU core number of node n; is the memory requirement for VNF type f, in GB; is the disk storage requirement for VNF type f, in TB; The link bandwidth resource constraint: When the bandwidth utilization rate of the physical link l is, increase the penalty weight hop(l) × 1.5 based on the bandwidth overhead; Wherein: is the bandwidth requirement of the virtual link e of service chain i, with the unit of Mbps; is a binary variable indicating whether the virtual link e of service chain i is mapped to the physical link l; B l is the total bandwidth capacity of the physical link l, with the unit of Mbps.

5. The network security isolation method based on the 5G network slicing technology according to claim 4, characterized in that, The method for applying the physical isolation degree constraint, so that the VNF of each service chain exclusively occupies a physical node and does not share physical resources with other service chains includes: The physical isolation constraint includes: Node-level physical isolation: Wherein: is to traverse all high-security-level service chains \(i\in I\) high and iterate over each high-security-level service chain; is to traverse all VNF instances \(f\in F\) of a certain service chain \(i\) i , that is, iterate over each VNF in the service chain \(i\); Link-level physical isolation: Wherein: Traverse all non-high-security-level service chains; Traverse all virtual links e of the current outer service chain i and check whether it is mapped to the physical link l; Is a set of high-security-level service chains. When the constraint takes effect, it prohibits the VNFf' of other service chains from sharing the node n with the high-security service chain i; The calculation method of the physical isolation degree index is as follows: The constraint is ISO_degree ≥ γ, where the physical isolation degree threshold γ ∈ [0, 1]; where: N(i) represents the set of physical nodes occupied by service chain i; γ is the preset physical isolation degree threshold; I high is a subset of service chains with high security levels; |N| is the total number of physical nodes in the entire physical network.

6. The network security isolation method based on 5G network slicing technology according to claim 5, characterized in that, The method for constructing an end-to-end delay model and imposing constraints on propagation delay, transmission delay, queuing delay, and processing delay includes: Decompose the end-to-end delay constraint into the following components: Wherein: is the end-to-end delay; is the propagation delay; is the transmission delay; is the queuing delay; is the processing delay; D max is the set maximum allowable end-to-end delay; Propagation delay Where: d l is the length of the physical link l, in km; v is the signal propagation speed; δ el ∈ {0, 1} indicates whether the virtual link e passes through the physical link l, which is determined by determined; Transmission delay Where: B e is the data volume of the virtual link e of service chain i, unit: MB; c l is the transmission rate of the physical link l, unit: MB / s Queuing delay Wherein: is the bandwidth utilization rate of link l; is the bandwidth requirement of virtual link e of service chain i; Bl is the total bandwidth capacity of physical link l, with the unit of Mbps; is a binary variable, indicating whether virtual link e of service chain i is mapped to physical link l. It takes 1 when virtual link e of service chain i is mapped to physical link l, otherwise it takes 0; ∑ i∈I represents the traversal of all service chains; i: service chain number, belonging to the service chain set; I: the set of service chains that have been deployed or to be deployed in the current system; represents the traversal of all virtual links of service chain i; e: virtual link number of service chain i, belonging to the virtual link set Ei of this service chain; Ei: virtual link set of service chain i; Processing delay: Where: is the request arrival rate of VNF v; is the service rate of VNF v, where α is the VNF processing efficiency coefficient (α ∈ [0.7, 0.9]), and the stability condition λ v < μ v ; is the CPU resource requirement of VNF v; x v,n ∈ {0, 1} is a binary variable indicating whether VNF v is deployed on node n; is the remaining CPU resource amount of node n.

7. The network security isolation method based on 5G network slicing technology according to claim 6, characterized in that, The steps for the hypergraph transformation and solution include: Construct a weighted hypergraph model: Map the service chain deployment problem to a weighted hypergraph \(g=(V,\varepsilon,W)\), where: Each service chain \(i\in I\) corresponds to a hyperedge \(\varepsilon_i\), and the set of physical nodes it covers is i.e., the deployment nodes of all VNFs of service chain \(i\); The node weight represents the comprehensive remaining resources of node \(n\); The hyperedge weight is defined as the negative value of the total deployment cost of service chain \(i\) , and the negative value indicates that maximizing the weight is equivalent to minimizing the cost; where: \(H(\varepsilon\) i ) is the set of physical nodes covered by hyperedge \(\varepsilon\) i ; \(W\) n is the comprehensive remaining resource weight of node \(n\); \(w(\varepsilon\) i ) is the hyperedge weight of service chain \(i\), i.e., the negative value of the total cost; \(V\) is the set of nodes of the hypergraph, corresponding to the physical node set \(N\); \(\varepsilon\) is the set of hyperedges of the hypergraph, corresponding to the service chain set \(I\); Generate an initial feasible solution: Randomly select a deployment plan that meets the following conditions Node-level constraints: node resource capacity, physical isolation, and mapping uniqueness; link-level constraints: bandwidth capacity and path hop count limit; if a feasible solution cannot be generated, reject the service chain request; Neighborhood operation and iterative optimization: The local search algorithm adopts a simulated annealing strategy and performs the following operations: VNF Node Migration: Select VNFf ∈ F of service chain i i , migrate it from node n to n′, and the following conditions need to be met: resource capacity Physical isolation requirements For high-security service chain i ∈ I high ; Link path remapping: Replace the physical path P i of the virtual link e ∈ E e with a path P e ′ with fewer hops, subject to: bandwidth constraints delay constraints where: P e is the set of physical paths of the virtual link e; Weight evaluation and solution update: Calculate the weight change ΔW of the hyperedge subset of the neighborhood solution, where ΔW = W new - W old , where: W new = ∑ εi∈ε′ w(ε i ), where ε' is the set of hyperedges affected by the operation; acceptance criterion: if ΔW > 0, directly update the solution; otherwise, accept it with probability p = e ΔW / T ; where ΔW is the weight difference between the neighborhood solution and the original solution; W new , W old are the total weights of the hyperedge subsets of the neighborhood solution and the original solution respectively, and T is the temperature parameter; Termination condition determination: Stop the iteration when any of the following conditions is met: the total weight has not been improved for K = 50 consecutive iterations; the cumulative calculation time ≥ T max = 1 second; no better solution can be generated by all neighborhood operations; where: T max is the maximum allowable calculation time of the algorithm, and K is the termination threshold of the non-improved iteration of the local search algorithm.

8. A computer device, characterized in that, Including a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the computer device implements the method according to any one of claims 1 to 7.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the computer device, it implements the method according to any one of claims 1 to 7.