Method and apparatus for resource isolation on network slices
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ALCATEL LUCENT SHANGHAI BELL CO LTD
- Filing Date
- 2023-08-14
- Publication Date
- 2026-05-29
AI Technical Summary
Existing network slice resource isolation mechanisms only focus on the network slice and network slice subnet layers, failing to effectively coordinate isolation strategies between the management layer and the network layer. This results in compromised or malicious low-security configurations potentially affecting highly sensitive slices, undermining isolation and access control.
By creating Network Slice Management Object (NS MOI) instances and generating isolation groups based on security requirements, sending NSS MOI requests to third-party network nodes, receiving and storing identifiers, the isolation requirements of Network Functions (NFs) are ensured to meet security standards, interactions between different isolation groups are restricted, and the correct routing of signaling and data services is ensured.
It achieves effective isolation of network functions (NFs), ensures the correct routing of signaling messages and data services, avoids isolation breaches caused by low security configurations, and meets the security requirements of vertical applications.
Smart Images

Figure CN122122957A_ABST
Abstract
Description
Technical Field
[0001] The various exemplary embodiments disclosed herein relate generally to communication technologies, and more specifically to methods and apparatus for resource isolation on network slices. Background Technology
[0002] In current communication systems such as 3GPP 5G NR (3rd Generation Partnership Project, 5th Generation, New Radio), network slicing enables businesses and operators to address specific requirements, including security requirements from different market segments.
[0003] Some slices need to be isolated from each other because a poorly configured or maliciously compromised slice may affect highly sensitive slices and compromise isolation and / or access controls.
[0004] However, slice resource isolation is currently focused only on the network slice and network slice subnet layers, so that the network slice provider (NSP) can receive slice isolation requests from the network slice consumer (NSC) and translate the requests to a lower layer (network slice subnet layer). Summary of the Invention
[0005] This summary is provided to introduce, in a simplified form, some aspects further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter.
[0006] Certain aspects of this disclosure and its embodiments can provide solutions to these or other challenges. Various embodiments are presented herein to address one or more problems disclosed herein. Specific methods and apparatus for resource isolation on network slices can be provided.
[0007] A first aspect of this disclosure provides a method performed by a first network node. The method includes: receiving from a second network node a first request for creating a network slice, the first request including at least one security requirement; creating a network slice management object instance (NS MOI); providing a group for the NS MOI based at least on the at least one security requirement; sending to a third network node a second request for at least one network slice subnet management object instance (NSS MOI), wherein the second request includes at least the at least one security requirement and an identifier for the group; receiving from the third network node a response to the second request, the response including at least one identifier for the at least one NSS MOI; storing the at least one identifier for the at least one NSS MOI; and sending to the second network node a response to the first request, the response including at least the identifier for the NS MOI.
[0008] In an exemplary embodiment of this disclosure, the at least one NSS MOI includes: at least one Core Network Slice Subnet Management Object Instance (CN NSS MOI), and / or at least one Radio Access Network Slice Subnet Management Object Instance (RAN NSS MOI). The first network node also creates a root network slice subnet management object instance (NSS MOI). The group includes an isolated group or a shared group. The group is also provided for the root NSS MOI.
[0009] In an exemplary embodiment of this disclosure, when no matching group exists for the NS MOI and / or the root NSS MOI, the group is created by the first network node, and the at least one CN NSS MOI and / or the at least one RAN NSS MOI is created by the third network node; or when a matching group exists for the NS MOI and / or the root NSS MOI, the group is assigned by the first network node, and the at least one CN NSS MOI and / or the at least one RAN NSS MOI is updated by the third network node.
[0010] In an exemplary embodiment of this disclosure, the first request further includes a list of service profiles, each service profile including an application descriptor; and the at least one security requirement includes a list of security levels or security features.
[0011] In an exemplary embodiment of this disclosure, the group includes an isolation profile based on at least one security requirement; the isolation profile includes group resource isolation rules; the group resource isolation rules include at least: resource type, isolation rules and / or security criteria; the resource type includes at least one of the following: network function type, network function, database or communication interface; and the security criteria include a list of security levels or security features.
[0012] In an exemplary embodiment of this disclosure, the first network node also provides the group based on regulations and operator policies.
[0013] In an exemplary embodiment of this disclosure, the second request further includes at least one slice profile for the at least one CN NSS MOI and / or the at least one RAN NSS MOI.
[0014] In an exemplary embodiment of this disclosure, the first network node includes: a network slice management service producer NSMS_P; the second network node includes: a network slice management service consumer NSMS_C; and the third network node includes: a network slice subnet management service producer NSSMS_P.
[0015] A second aspect of this disclosure provides a method performed by a second network node. The method includes: sending a first request to a first network node for the creation of a network slice, the first request including at least one security requirement; and receiving a response from the first network node to the first request, the response including at least an identifier of a network slice management object instance (NS MOI) provided at least based on the at least one security requirement.
[0016] In an exemplary embodiment of this disclosure, the first request for creating a network slice further includes an application descriptor; the response to the first request is also provided based on the application descriptor; the first network node includes a network slice management service producer NSMS_P; and the second network node includes a network slice management service consumer NSMS_C.
[0017] A third aspect of this disclosure provides a method performed by a third network node. The method includes: receiving from a first network node a second request for at least one NSS MOI, the second request including at least one security requirement; generating the at least one NSS MOI based at least on the second request; generating resource requirements and / or configurations associated with the at least one NSS MOI for core network functions and / or radio access network functions; sending the resource requirements and / or configurations to a fourth network node; and sending a response to the second request to the first network node, the response including at least one identifier of the at least one NSS MOI.
[0018] In an exemplary embodiment of this disclosure, the at least one NSS MOI includes: at least one CN NSS MOI and / or at least one RAN NSS MOI. The second request also includes: a group identifier, and at least one slice profile, each slice profile including at least one application descriptor.
[0019] In an exemplary embodiment of this disclosure, the third network node sets security standards and optional identifiers for network slice groups in at least one CN NSS MOI and / or at least one RAN NSS MOI based at least on the second request; and the third network node assigns one or more identifiers of network slice instance NSIs to CN NSS MOIs for the fifth-generation core network 5GC based at least on local policies.
[0020] In an exemplary embodiment of this disclosure, generating the at least one CN NSS MOI and / or at least one RAN NSS MOI includes: creating a root CN NSS MOI and / or a root RAN NSS MOI; creating a dedicated CN NSS MOI and / or a dedicated RAN NSS MOI for the dedicated resources of the root CN NSS MOI and / or the root RAN NSS MOI; and creating a shared CN NSS MOI and / or a shared RAN NSS MOI for the shared resources of the root CN NSS MOI and / or the root RAN NSS MOI, wherein the shared CN NSS MOI and / or the shared RAN NSS MOI may or may not have an NSS group.
[0021] In an exemplary embodiment of this disclosure, generating the at least one CN NSS MOI and / or at least one RAN NSS MOI further includes setting a resource sharing indicator for the dedicated CN NSS MOI and / or the dedicated RAN NSS MOI, or for the shared CN NSS MOI and / or the shared RAN NSS MOI.
[0022] In an exemplary embodiment of this disclosure, the third network node sets a first resource sharing indicator in the NSS MOI; when the first resource sharing indicator indicates that the NSS MOI is shared, the third network node divides the NSS MOI into a dedicated portion and a shared portion; when the dedicated portion is not empty, the third network creates a dedicated NSS MOI for the dedicated portion; and when the shared portion is not empty, the third network creates / updates a matching NSS MOI for the shared portion, wherein the matching NSS MOI has an NSS group, or the matching NSS MOI does not have the NSS group; and sets a second resource sharing indicator in the matching NSS MOI at least based on security standards and local policies.
[0023] In an exemplary embodiment of this disclosure, when the first resource sharing indicator indicates that the NSS MOI is private, the third network node sets the type of the NSS MOI to leaf NSS.
[0024] In an exemplary embodiment of this disclosure, the resource requirement and / or configuration includes slice information and network slice instance (NSI) information for configuring the network slice selection function (NSSF); and / or the resource requirement and / or configuration includes a mapping between at least one identifier of the application and at least one single network slice selection aid (S-NSSAI) for configuring the policy control function (PCF).
[0025] In an exemplary embodiment of this disclosure, the slice information includes network slice selection assistance information S-NSSAI and a corresponding identifier of NSI supporting each S-NSSAI, and the NSI information includes at least one identifier of NSI and at least one identifier of network slice isolation group associated with at least one identifier of NSI.
[0026] In an exemplary embodiment of this disclosure, the at least one S-NSSAI is based on at least one slice profile associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI; and the at least one S-NSSAI is used to generate User Equipment Routing Policy URSP rules for User Equipment (UE), which supports slices associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI.
[0027] In an exemplary embodiment of this disclosure, the at least one security requirement includes a list of security levels or security features.
[0028] In an exemplary embodiment of this disclosure, the group includes an isolation profile; the isolation profile includes group resource isolation rules; the group resource isolation rules include at least: resource type, isolation rules, and security criteria; the resource type includes at least one of the following: network function type, network function, database, or communication interface; and the security criteria include a list of security levels or security features.
[0029] In an exemplary embodiment of this disclosure, the first network node includes: a network slice management service producer NSMS_P; the third network node includes: a network slice subnet management service producer NSSMS_P; and the fourth network node includes at least one of the following: a network function management service producer NFMS_P, cloud infrastructure, a network slice selection function NSSF, or a policy control function PCF.
[0030] A fourth aspect of this disclosure provides a method performed by a fourth network node. The method includes receiving resource requests and / or configurations from a third network node. The resource requests and / or configurations are used to configure core network functions and / or radio access network functions associated with at least one NSS MOI.
[0031] In an exemplary embodiment of this disclosure, the at least one NSS MOI includes: at least one CN NSS MOI and / or at least one RAN NSS MOI.
[0032] In an exemplary embodiment of this disclosure, the resource requirements and / or configuration include: slice information and network slice instance (NSI) information, used to configure the network slice selection function (NSSF).
[0033] In an exemplary embodiment of this disclosure, the slice information includes network slice selection assistance information S-NSSAI and a corresponding identifier of NSI supporting each S-NSSAI, and the NSI information includes at least one identifier of NSI and at least one identifier of network slice isolation group associated with at least one identifier of NSI.
[0034] In an exemplary embodiment of this disclosure, during a mobility and session management signaling process, the NSSF sends at least one identifier for the NSI of the S-NSSAI to the Access and Mobility Management Function (AMF) based at least on the S-NSSAI and the corresponding identifier of the NSI supporting each S-NSSAI; or during a slice replacement process, the NSSF selects an alternative S-NSSAI based on the isolation group associated with the S-NSSAI and the corresponding identifier of the NSI supporting each S-NSSAI; or the NSSF checks whether the slice selected by the Application Function (AF) or the User Equipment (UE) for an application is in the same group defined in the User Equipment Routing Policy (URSP) associated with the application.
[0035] In an exemplary embodiment of this disclosure, the resource requirement and / or configuration includes: a mapping between at least one identifier of the application and at least one Single Network Slice Selection Assist Information (S-NSSAI) for configuring the Policy Control Function (PCF).
[0036] In an exemplary embodiment of this disclosure, the at least one S-NSSAI is based on at least one slice profile associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI; and the at least one S-NSSAI is used to generate User Equipment Routing Policy URSP rules for User Equipment (UE), which supports slices associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI.
[0037] In an exemplary embodiment of this disclosure, the PCF determines whether the slice selected by the application in the User Equipment Routing Policy (URSP) is in the same group.
[0038] In an exemplary embodiment of this disclosure, the third network node includes: a network slice subnet management service producer NSSMS_P; and the fourth network node includes at least one of the following: a network function management service producer NFMS_P, cloud infrastructure, a network slice selection function NSSF, or a policy control function PCF.
[0039] A fifth aspect of this disclosure provides a first network node including components configured to: receive from a second network node a first request for creating a network slice, the first request including at least one security requirement; create a network slice management object instance (NS MOI); provide a group for the NS MOI based at least on the at least one security requirement; send to a third network node a second request for at least one network slice subnet management object instance (NSS MOI), the second request including at least the at least one security requirement and an identifier of the group; receive from the third network node a response to the second request, the response including at least one identifier of the at least one NSS MOI; store the at least one identifier of the at least one NSS MOI; and send to the second network node a response to the first request, the response including at least the identifier of the NS MOI.
[0040] In exemplary embodiments of this disclosure, the component is also configured to perform a method according to any embodiment of the first aspect.
[0041] In an exemplary embodiment of this disclosure, the component includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the execution of a first network node.
[0042] A sixth aspect of this disclosure provides a second network node including components configured to: send a first request to a first network node for the creation of a network slice, the first request including at least one security requirement; and receive a response to the first request from the first network node, the response to the first request including at least an identifier of a network slice management object instance NS MOI, the identifier of the network slice management object instance NS MOI being provided at least based on the security requirement.
[0043] In exemplary embodiments of this disclosure, the component is also configured to perform a method according to any embodiment of the second aspect.
[0044] In an exemplary embodiment of this disclosure, the apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the execution of a second network node.
[0045] A seventh aspect of this disclosure provides a third network node including components configured to: receive from a first network node a second request for at least one NSS MOI, the second request including at least one security requirement; generate the at least one NSS MOI based at least on the second request; generate resource requirements and / or configurations for core network functions and / or radio access network functions associated with the at least one NSS MOI; send the resource requirements and / or configurations to a fourth network node; and send a response to the second request to the first network node, the response including at least one identifier of the at least one NSS MOI.
[0046] In exemplary embodiments of this disclosure, the component is also configured to perform a method according to any embodiment of the first aspect.
[0047] In an exemplary embodiment of this disclosure, the apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause execution of a third network node.
[0048] An eighth aspect of this disclosure provides a fourth network node, including components configured to: receive resource requests and / or configurations from a third network node. The resource requests and / or configurations are used to configure core network functions and / or radio access network functions associated with at least one NSS MOI.
[0049] In exemplary embodiments of this disclosure, the component is also configured to perform a method according to any embodiment of the second aspect.
[0050] In an exemplary embodiment of this disclosure, the component includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the execution of a fourth network node.
[0051] A ninth aspect of this disclosure provides a computer-readable storage medium that stores instructions that, when executed by at least one processor of a network node, cause the at least one processor of the network node to perform a method according to any embodiment of the first, second, third, and fourth aspects.
[0052] A tenth aspect of this disclosure provides an apparatus. The apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform at least any of the methods according to the embodiments of the first, second, third, and fourth aspects.
[0053] In exemplary embodiments of this disclosure, the component is or is included in a network node.
[0054] The embodiments described herein offer numerous advantages. According to embodiments of this disclosure, improved methods for resource isolation on network slices can be provided.
[0055] According to embodiments of this disclosure, exemplary embodiments of this disclosure propose a mechanism that allows for the determination of at least one NSS MOI in response to a request for the creation of a network slice that includes at least one security requirement. Isolation requirements for resources, particularly isolation requirements for network functions (NFs) defined in at least one NSS MOI, can be defined as satisfying at least one security requirement.
[0056] Therefore, interactions between NFs belonging to different isolation groups can be restricted, UE signaling messages can be routed to the correct control plane (CP) NF, and UE data services can be routed to the correct user plane function (UPF) without compromising isolation requirements. Attached Figure Description
[0057] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more apparent from the following detailed description with reference to the accompanying drawings, in which the same reference numerals or letters are used to denote the same or equivalent elements. The drawings are illustrated to facilitate a better understanding of the embodiments of the present disclosure and are not necessarily drawn to scale, wherein: Figure 1 This is a diagram showing some exemplary slice isolation groups.
[0058] Figure 2 This is a diagram showing the slice isolation for the UE.
[0059] Figure 3 This is a diagram illustrating the Network Resource Model (NRM) used for network slicing.
[0060] Figure 4 This is a graph showing the cross-layer resource distribution used for network slicing.
[0061] Figure 5 This is a diagram illustrating unintended resource isolation used for network slicing.
[0062] Figure 6 This is a flowchart illustrating a method performed by a first network node according to an exemplary embodiment of the present disclosure.
[0063] Figure 7 This is a flowchart illustrating a method performed by a second network node according to an exemplary embodiment of the present disclosure.
[0064] Figure 8A This is a flowchart illustrating a method performed by a third network node according to an exemplary embodiment of the present disclosure.
[0065] Figure 8B This illustrates exemplary embodiments according to the present disclosure, such as Figure 8A A flowchart of another step in the method shown.
[0066] Figure 9 This is a flowchart illustrating a method performed by a fourth network node according to an exemplary embodiment of the present disclosure.
[0067] Figure 10 This refers to the configuration of network slice subnets and NFs in a 5G network according to embodiments of this disclosure.
[0068] Figure 11 This is a diagram illustrating the process for network slicing deployment and resource isolation according to Embodiment 1 of this disclosure.
[0069] Figure 12 This is a diagram illustrating the process for creating an NSS according to Embodiment 2 of this disclosure.
[0070] Figure 13 This is a block diagram illustrating an exemplary structure for a first network node according to an exemplary embodiment of the present disclosure.
[0071] Figure 14 This is a block diagram illustrating an exemplary structure for a second network node according to an exemplary embodiment of the present disclosure.
[0072] Figure 15 This is a block diagram illustrating an exemplary structure for a third network node according to an exemplary embodiment of the present disclosure.
[0073] Figure 16 This is a block diagram illustrating an exemplary structure for a fourth network node according to an exemplary embodiment of the present disclosure.
[0074] Figure 17 This is a block diagram illustrating an apparatus / computer-readable storage medium according to embodiments of the present disclosure.
[0075] Figure 18 This is a block diagram illustrating an exemplary device unit for a first network node suitable for performing a method according to an embodiment of the present disclosure.
[0076] Figure 19 This is a block diagram illustrating an exemplary device unit for a second network node suitable for performing a method according to an embodiment of the present disclosure.
[0077] Figure 20 This is a block diagram illustrating an exemplary device unit for a third network node suitable for performing a method according to an embodiment of the present disclosure.
[0078] Figure 21This is a block diagram illustrating an exemplary device unit for a fourth network node suitable for performing a method according to an embodiment of the present disclosure. Detailed Implementation
[0079] Embodiments of this disclosure have been described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed for better understanding only and not to limit the scope of this disclosure. The features, advantages, and characteristics described in this disclosure may be combined in any suitable manner in one or more embodiments.
[0080] Generally, all terms used herein will be interpreted according to their ordinary meaning in the relevant art, unless a different meaning is clearly given and / or implied from the context in which they are used. The steps of any method disclosed herein need not be performed in the exact order disclosed unless the context clearly gives and / or implies otherwise. Where appropriate, any feature of any embodiment disclosed herein may be applied to any other embodiment.
[0081] As used herein, the term "network" or "communication network" refers to a network that conforms to any suitable communication standard, such as the Internet or any wireless network. For example, wireless communication standards may include WLAN (Wireless Local Area Network), New Radio (NR), Long Term Evolution (LTE), LTE-Advanced, 5G NR, etc. In the following description, the terms "network" and "system" are used interchangeably.
[0082] The term "network node" refers to a network device, network entity, network function, or any other device (physical or virtual) in a communication network. For example, a network node in a network can include a base station (BS), an access point (AP), or any other suitable device in a wireless communication network. A BS can be, for example, a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), a next-generation Node B (gNodeB or gNB), a remote radio unit (RRU), a radio head unit (RH), a remote radio head unit (RRH), a relay, or a low-power node (such as a femtosecond, picosecond, etc.).
[0083] The term "terminal device" refers to any terminal device that can access a communication network and receive services from it. By way of example and not limitation, a terminal device refers to a mobile terminal, user equipment (UE), non-AP device (such as a non-AP site (STA)), or other suitable device. Terminal devices can include, but are not limited to, mobile phones, cellular phones, smartphones, wearable devices, in-vehicle wireless terminal equipment, vehicles, etc.
[0084] As an example, a terminal device can refer to a device configured to communicate according to one or more communication standards published by any standards organization (e.g., the 3rd Generation Partnership Project, 3GPP).
[0085] As another example, in the Internet of Things (IoT) scenario, a terminal device can represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another terminal device and / or network device. Specific examples of such machines or devices are sensors, metering devices (such as power meters), industrial machinery or household or personal appliances (such as refrigerators, televisions), and personal wearable devices (such as watches). In other scenarios, a terminal device can represent a vehicle or other device capable of monitoring and / or reporting its operational status or other functions associated with its operation.
[0086] It should be understood that although the terms “first” and “second” may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.
[0087] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements is connected by “and” or “or”, means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.
[0088] Exemplary embodiments of this disclosure relate to methods and apparatus for resource isolation on network slices.
[0089] Slice isolation management is being developed within the Services and Systems (SA) 5 working group. Network slicing enables enterprises and operators to address specific requirements, including security requirements from different market segments. Impaired or maliciously configured, low-security slices can compromise highly sensitive slices, disrupting isolation and / or access controls.
[0090] In 3GPP SA5, slice isolation management was studied in the 3GPP technical reports, and slice isolation requirements are defined in TR 28.811 V 17.0.0 and TS 28.530 V 17.4.0. Therefore, shared / isolated groups with isolation profiles / policies for each group are proposed to achieve resource isolation, as shown in the following example.
[0091] Figure 1 This is a diagram showing some exemplary slice isolation groups.
[0092] Tenant isolation is illustrated below as an example. Specifically, tenant-based isolation of managed resources (e.g., access network, AN, core network, CN, transport network, TN) can be shown.
[0093] As shown in IG_Tenant-A 101, tenant A's enhanced mobile broadband (eMBB) slice and massive Internet of Things (mIoT) slice are assigned to the same isolation group, and no isolation is required between slice A_eMBB-1 and slice A_mIoT-1. However, tenant A's slices need to be logically isolated from other tenant slices.
[0094] As shown in IG_Tenant-B102, tenant B's Ultra-Reliable Low-Latency Communication (URLLC) slice (slice B_uRLL-1) is physically / logically isolated from other slices.
[0095] As shown in IG_SST (slice / service type)-eMBB-public 103, the operator's two eMBB slices (slice O_e MBB-1 and slice O_e MBB-2) share resources but are logically isolated from other tenant slices.
[0096] Figure 2 This is a diagram showing the slice isolation for the UE.
[0097] Slice isolation has also been developed in other 3GPP groups. Below are different examples of resource isolation between slices for different UEs.
[0098] A slice can be completely isolated from other slices, both in the path from the Radio Access Network (RAN) to the transport link / layer and then to the core network (CN), and in both the control plane and the user plane. Therefore, dedicated resources are allocated to slices such as S-NSSAI#1.
[0099] Slices can be partially isolated from other slices. For example, distributed units (DUs) and other control plane (CP) network functions (NFs) can be shared, but dedicated user plane (UP) related NFs are used for, for example, S-NSSAI#3.
[0100] A slice can share all function calls (NFs) with other slices. For example, DU, centralized unit (CU), CP, and UP NFs can be shared for, for example, S-NSSAI#4 and 5.
[0101] Figure 3 This is a diagram illustrating the Network Resource Model (NRM) used for network slicing.
[0102] The NRM for network slices, network slice subnets and their associated network slices is defined as supporting network slice management and orchestration.
[0103] Based on UML, Figure 3 In the diagram, the cluster is graphically represented as a hollow rhombus shape, indicated by an asterisk. This indicates multiple instances, '1' indicates one instance, and the arrow indicates directional association.
[0104] The relationships between Network Slice (Information Object Class) 311, Service Profile (Data Type) 321, Network Slice Subnet (Information Object Class) 322, Slice Profile (Data Type) 331, Managed Function (Information Object Class) 332, Network Service (Open Model Class, Preliminary) 333, Endpoint (EP)_Transport (Information Object Class) 334 and Virtual Network Function (VNF) (Open Model Class, Preliminary) 341 can be illustrated.
[0105] Some research has been conducted on this topic. For example, 3GPP TR 28.811 V 17.0.0 describes use cases, requirements, and solutions for isolating managed data and managed resources. A potential solution with isolation groups is based on WO2021 / 15946. It provides a way to collect network slices with the same security attributes or within the same organization and share resources among slices within that group, while isolating resources from slices in other groups.
[0106] Other solutions introduce a mechanism to extend ServiceProfile and SliceProfile with additional attributes that network service consumers (NSCs) and network service providers (NSPs) can use to select isolation groups with appropriate isolation requirements and request the creation of network slices. Additionally, NSCs can use the same attributes to request the association or modification of isolation groups, and thus request the isolation requirements for the created slices.
[0107] New data types can be further introduced, where NSC can specify composite conditions for NSP to select isolation groups.
[0108] 3GPP Release 18 (R18) Work Item (WI) also studies Network Slice Rules (NSRULE). It updates the serviceProfile and sliceProfile to be able to store rule information, including groupings, which provides additional input on the conditions under which Management Service (MnS) producers can share network slices or network slice subnets among multiple allocation requests and profiles.
[0109] Figure 4 This is a graph showing the cross-layer resource distribution used for network slicing.
[0110] like Figure 4 As shown, vertically, end-to-end slices cover the logical network, network resources, and infrastructure layers. For example, S-NSSAI-0 covers applications (Layer 4, L4), logical networks (L3), network resources (L2), virtualized resources (L1), and physical resources (L0).
[0111] and Figure 2 In contrast, in the horizontal direction, end-to-end slices include segments of UE, RAN, transport, CN, and data network (DN).
[0112] Previous research has focused on isolating slice resources only at the network slice and network slice subnet layers to enable network slice providers (NSPs) to receive slice isolation requests from network slice consumers (NSCs) and translate those requests to a lower layer (network slice subnet layer). However, the network functions involved have not been considered in detail.
[0113] Figure 5 This is a diagram illustrating unintended resource isolation used for network slicing.
[0114] like Figure 5 As shown, operators can use network slicing to allocate virtual networks and network resources to specific vertical applications, and expect to isolate resources for application use based on corresponding policies in the network and existing isolation solutions. For example, for slice-aware access control of 5GC based on service interface (SBI), consider single network selection auxiliary information (S-NSSAI) to select the correct CP or UP NF, etc.
[0115] However, due to a lack of coordination between the management and network layers, isolation policies and related parameters may not be correctly provided on NFs, rendering all isolation solutions in the control plane ineffective. For example, the management plane may expect to isolate the resources of applications in S-NSSAI#3 from those in S-NSSAI#4 and S-NSSAI#5, but misconfiguration of Network Slice Information (NSI) and S-NSSAI in NFs with a lack of a standardized information model could allow NFs in S-NSSAI#4 to access NF services of NFs in S-NSSAI#3. Furthermore, compromised or maliciously configured, low-security slices could affect highly sensitive slices, such as stealing services / resources and data from mission-critical applications.
[0116] Also refer to Figure 2Various isolation models can be deployed based on isolation and security requirements, such as fully isolated slices, fully shared slices, and partially shared slices. The association between NSI IDs and S-NSSAIs is not correctly reflected in the NRM defined in SA5, and isolation or sharing-related requirements / policies are not mapped to the NRM of 5GC or RAN NFs defined in SA5 and the data model defined in Communication Technology (CT). This may lead to incorrect NSIs, and consequently incorrect NFs, being selected for signaling or user services, especially when more than one NSI ID is supported by a "shared" NF in a partially isolated scenario.
[0117] When an S-NSSAI becomes unavailable or congested, a network slice replacement feature was introduced in Release 18 to replace it with an alternative S-NSSAI. Without proper configuration, Access and Mobility Management / Policy Control / Network Slice Selection (AMF / PCF / NSSF) functions can select an alternative S-NSSAI that requires secure isolation from the original S-NSSAI, thus violating security / isolation requirements for vertical applications.
[0118] The embodiments disclosed herein can provide solutions to improve this situation.
[0119] Figure 6 This is a flowchart illustrating a method performed by a first network node according to an exemplary embodiment of the present disclosure.
[0120] like Figure 6 As shown, method 600 includes: step S602, receiving a first request from a second network node for creating a network slice, including at least one security requirement; step S604, creating a network slice management object instance (NS MOI); step S606, providing a group for the NS MOI based on at least one security requirement; step S608, sending a second request to a third network node for at least one network slice subnet management object instance (NSS MOI), wherein the second request includes at least the at least one security requirement and an identifier for the group; step S610, receiving a response to the second request from the third network node, the response to the second request including at least one identifier for at least one NSS MOI; step S612, storing at least one identifier for the at least one NSS MOI; and step S614, sending a response to the first request to the second network node, the response to the first request including at least the identifier for the NS MOI.
[0121] According to embodiments of this disclosure, exemplary embodiments of this disclosure propose a mechanism that allows for the determination of at least one NSS MOI in response to a request for the creation of a network slice that includes at least one security requirement. Isolation requirements for resources, particularly isolation requirements for network functions (NFs) defined in at least one NSS MOI, can be defined as satisfying at least one security requirement. It should be noted that, for clarity, full terms such as NS MOI and NSS MOI are used herein. However, sometimes in this or other disclosures, other terms such as NS / NSI, NSS, etc., may also be used to indicate instances associated with a network slice or a network slice subnet.
[0122] Therefore, interactions between NFs belonging to different isolation groups can be restricted, UE signaling messages can be routed to the correct control plane (CP) NF, and UE data services can be routed to the correct user plane function (UPF) without compromising isolation requirements.
[0123] In an exemplary embodiment of this disclosure, the at least one NSS MOI includes: at least one core network slice subnet management object instance (CN NSS MOI) and / or at least one radio access network slice subnet management object instance (RAN NSS MOI); the first network node also creates a root network slice subnet management object instance (NSS MOI); the group includes an isolated group or a shared group; and the group is also provided for the root NSS MOI.
[0124] According to embodiments of this disclosure, specific types of network functions (such as CN NF, RAN NF, or TN NF) can be isolated when needed. In particular, groups can be configured. These groups can clearly indicate the isolation or sharing relationships between different NSs or even NSSs. For example, different NSs within or associated with the same group can share communication resources associated with that group while remaining isolated from communication resources in other groups.
[0125] In an exemplary embodiment of this disclosure, when no matching group exists for the NS MOI and / or the root NSS MOI, the group is created by the first network node, and the at least one CN NSS MOI and / or the at least one RAN NSS MOI is created by the third network node; or when a matching group exists for the NS MOI and / or the root NSS MOI, the group is assigned by the first network node, and the at least one CN NSS MOI and / or the at least one RAN NSS MOI is updated by the third network node. According to embodiments of this disclosure, groups can be created or updated.
[0126] According to embodiments of this disclosure, two types of root / top-level (i.e., higher-level) NSSs can be utilized. The first is a top-level / root end-to-end (E2E) NSS, which splices together a CN top-level NSS, a RAN top-level NSS, and possible transport NSSs to form an E2E NSS to serve network slices. Root / top-level network slice subnets (NSS) are described in TS 28.530 V 17.4.0 and 28.541 V 18.4.0. The second type of top-level NSS is a top-level NSS within a specific domain (e.g., a CN or RAN domain), which is created in each domain to support specific isolation groups for network slices. Leaf (i.e., lower-level) NSSs are NSSs that only include dedicated / isolated resources and are not shared with other NSSs. This type of NSS can be used to better illustrate the isolation / sharing relationships between different NSs.
[0127] In an exemplary embodiment of this disclosure, the first request further includes a list of service profiles, each service profile including an application descriptor; and the at least one security requirement includes a list of security levels or security features.
[0128] According to embodiments of this disclosure, the group can be associated with a specific application by using an application descriptor.
[0129] In an exemplary embodiment of this disclosure, the group includes an isolation profile based on at least one security requirement; the isolation profile includes group resource isolation rules; the group resource isolation rules include at least: resource type, isolation rules and / or security criteria; the resource type includes at least one of the following: network function type, network function, database or communication interface; and the security criteria include a list of security levels or security features.
[0130] According to embodiments of this disclosure, group resource isolation rules are clearer, thus specific NFs or other communication resources will be better isolated.
[0131] In an exemplary embodiment of this disclosure, the first network node also provides the group based on regulations and operator policies.
[0132] In an exemplary embodiment of this disclosure, the second request further includes at least one slice profile for the at least one CN NSS MOI and / or the at least one RAN NSS MOI.
[0133] In an exemplary embodiment of this disclosure, the first network node includes: a network slice management service producer NSMS_P; the second network node includes: a network slice management service consumer NSMS_C; and the third network node includes: a network slice subnet management service producer NSSMS_P.
[0134] Figure 7This is a flowchart illustrating a method performed by a second network node according to an exemplary embodiment of the present disclosure.
[0135] like Figure 7 As shown, method 700 includes: step S702, sending a first request for network slice creation to a first network node, the first request including at least one security requirement; and step S704, receiving a response to the first request from the first network node, the response including at least an identifier of a network slice management object instance NS MOI provided based on at least the at least one security requirement.
[0136] In an exemplary embodiment of this disclosure, the first request for creating a network slice further includes an application descriptor; the response to the first request is also provided based on the application descriptor; the first network node includes a network slice management service producer NSMS_P; and the second network node includes a network slice management service consumer NSMS_C.
[0137] Figure 8A This is a flowchart illustrating a method performed by a third network node according to an exemplary embodiment of the present disclosure.
[0138] like Figure 8A As shown, method 800 includes: step S802, receiving a second request from a first network node for at least one NSS MOI, wherein the second request includes at least one security requirement; step S804, generating at least one NSS MOI based on the second request; step S806, generating resource requirements and / or configurations related to the at least one NSS MOI for core network functions and / or radio access network functions; step S808, sending the resource requirements and / or configurations to a fourth network node; and step S810, sending a response to the second request to the first network node, the response including at least one identifier of the at least one NSS MOI.
[0139] According to embodiments of this disclosure, resource requirements and / or configurations for core network functions and / or radio access network functions can be generated, at least based on a second request. Therefore, core network functions and / or radio access network functions can be configured, at least according to security requirements. Isolation requirements for communication resources (especially NFs) can be better met.
[0140] In an exemplary embodiment of this disclosure, the at least one NSS MOI includes: at least one CN NSS MOI and / or at least one RAN NSS MOI. The second request also includes: a group identifier, and at least one slice profile, each slice profile including at least one application descriptor.
[0141] In an exemplary embodiment of this disclosure, the third network node sets security standards and optional identifiers for network slice groups in at least one CN NSS MOI and / or at least one RAN NSS MOI based at least on the second request; and the third network node assigns one or more identifiers of network slice instance NSIs to CN NSS MOIs for the fifth-generation core network 5GC based at least on local policies.
[0142] Figure 8B This illustrates exemplary embodiments according to the present disclosure, such as Figure 8A A flowchart of another step in the method shown.
[0143] In an exemplary embodiment of this disclosure, generating at least one CN NSS MOI and / or at least one RAN NSS MOI includes: step S812, creating a root CN NSS MOI and / or a root RAN NSS MOI; step S814, creating a dedicated CN NSS MOI and / or a dedicated RAN NSS MOI for the dedicated resources of the root CN NSS MOI and / or the root RAN NSS MOI; and step S816, creating a shared CN NSS MOI and / or a shared RAN NSS MOI with or without an NSS group for the shared resources of the root CN NSS MOI and / or the root RAN NSS MOI.
[0144] In an exemplary embodiment of this disclosure, generating at least one CN NSS MOI and / or at least one RAN NSS MOI further includes: step S818, setting a resource sharing indicator for a dedicated CN NSS MOI and / or a dedicated RAN NSS MOI or for a shared CN NSS MOI and / or a shared RAN NSS MOI.
[0145] In an exemplary embodiment of this disclosure, the third network node sets a first resource sharing indicator in the NSS MOI; when the first resource sharing indicator indicates that the NSS MOI is shared, the third network node divides the NSS MOI into a dedicated portion and a shared portion; when the dedicated portion is not empty, the third network creates a dedicated NSS MOI for the dedicated portion; and when the shared portion is not empty, the third network creates / updates a matching NSS MOI for the shared portion, wherein the matching NSS MOI has an NSS group, or the matching NSS MOI does not have the NSS group; and sets a second resource sharing indicator in the matching NSS MOI at least based on security standards and local policies.
[0146] In an exemplary embodiment of this disclosure, when the first resource sharing indicator indicates that the NSS MOI is private, the third network node sets the type of the NSS MOI to leaf NSS.
[0147] According to embodiments of this disclosure, dedicated or shared resources (especially NFs) can be better allocated and configured in NSS MOI.
[0148] In an exemplary embodiment of this disclosure, the resource requirement and / or configuration includes slice information and network slice instance (NSI) information for configuring the network slice selection function (NSSF); and / or the resource requirement and / or configuration includes a mapping between at least one identifier of the application and at least one single network slice selection aid (S-NSSAI) for configuring the policy control function (PCF).
[0149] In an exemplary embodiment of this disclosure, the slice information includes network slice selection assistance information S-NSSAI and a corresponding identifier of NSI supporting each S-NSSAI, and the NSI information includes at least one identifier of NSI and at least one identifier of network slice isolation group associated with at least one identifier of NSI.
[0150] In an exemplary embodiment of this disclosure, the at least one S-NSSAI is based on at least one slice profile associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI; and the at least one S-NSSAI is used to generate User Equipment Routing Policy URSP rules for User Equipment (UE), which supports slices associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI.
[0151] In an exemplary embodiment of this disclosure, at least one security requirement includes a list of security levels or security features.
[0152] In an exemplary embodiment of this disclosure, the group includes an isolation profile; the isolation profile includes group resource isolation rules; the group resource isolation rules include at least: resource type, isolation rules, and security criteria; the resource type includes at least one of the following: network function type, network function, database, or communication interface; and the security criteria include a list of security levels or security features.
[0153] According to embodiments of this disclosure, the requirements and / or configuration for NFs can be known by the NSSF and / or PCF. NFs in slice CPs and UPs will be better configured and / or selected, thus better meeting isolation requirements.
[0154] In an exemplary embodiment of this disclosure, the first network node includes: a network slice management service producer NSMS_P; the third network node includes: a network slice subnet management service producer NSSMS_P; and the fourth network node includes at least one of the following: a network function management service producer NFMS_P, cloud infrastructure, a network slice selection function NSSF, or a policy control function PCF.
[0155] Figure 9 This is a flowchart illustrating a method performed by a fourth network node according to an exemplary embodiment of the present disclosure.
[0156] Method 900 includes: step S902, receiving resource requirements and / or configurations from a third network node. The resource requirements and / or configurations are used to configure core network functions and / or radio access network functions associated with at least one NSS MOI.
[0157] In an exemplary embodiment of this disclosure, at least one NSS MOI includes: at least one CN NSS MOI and / or at least one RAN NSS MOI.
[0158] In an exemplary embodiment of this disclosure, resource requirements and / or configurations include: slice information and network slice instance (NSI) information, used to configure the network slice selection function (NSSF).
[0159] In an exemplary embodiment of this disclosure, the slice information includes network slice selection assistance information S-NSSAI and a corresponding identifier of NSI supporting each S-NSSAI, and the NSI information includes at least one identifier of NSI and at least one identifier of network slice isolation group associated with at least one identifier of NSI.
[0160] In an exemplary embodiment of this disclosure, during a mobility and session management signaling process, the NSSF sends at least one identifier for the NSI of the S-NSSAI to the Access and Mobility Management Function (AMF) based at least on the S-NSSAI and the corresponding identifier of the NSI supporting each S-NSSAI; or during a slice replacement process, the NSSF selects an alternative S-NSSAI based on the isolation group associated with the S-NSSAI and the corresponding identifier of the NSI supporting each S-NSSAI; or the NSSF checks whether the slice selected by the Application Function (AF) or the User Equipment (UE) for an application is in the same group defined in the User Equipment Routing Policy (URSP) associated with the application.
[0161] In an exemplary embodiment of this disclosure, the resource requirement and / or configuration includes: a mapping between at least one identifier of the application and at least one Single Network Slice Selection Assist Information (S-NSSAI) for configuring the Policy Control Function (PCF).
[0162] In an exemplary embodiment of this disclosure, the at least one S-NSSAI is based on at least one slice profile associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI; and the at least one S-NSSAI is used to generate User Equipment Routing Policy URSP rules for User Equipment (UE), which supports slices associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI.
[0163] In an exemplary embodiment of this disclosure, the PCF determines whether the slice selected by the application in the User Equipment Routing Policy (URSP) is in the same group.
[0164] In an exemplary embodiment of this disclosure, the third network node includes: a network slice subnet management service producer NSSMS_P; and the fourth network node includes at least one of the following: a network function management service producer NFMS_P, cloud infrastructure, a network slice selection function NSSF, or a policy control function PCF.
[0165] Therefore, embodiments of this disclosure will propose solutions on how to map isolation requirements to NF configurations, restrict interactions between NFs belonging to different isolation groups, and enable UE signaling messages to be routed to the correct control plane (CP) NF and user traffic to the correct user plane function (UPF) without compromising isolation requirements.
[0166] The embodiments of this disclosure can: Extend the management services and processes related to network slicing and network functions to support proper resource provisioning and isolation during network slice deployment and updates. Isolation modes can be fully isolated (dedicated NFs / resources for slices), partially isolated (sharing some NFs, such as CP NFs, while other NFs are separate / dedicated, such as UP NFs), or fully shared (sharing all NFs between slices).
[0167] Extend the NRM of NF to support resource (NF or NF service) selection and isolation during signaling.
[0168] Figure 10 This refers to the configuration of network slice subnets and NFs in a 5G network according to embodiments of this disclosure.
[0169] After enhancement, it will be as follows Figure 10To view the configuration of network slice subnets and NFs in a 5G network, as shown in the example.
[0170] Because of the coordination between the management and network layers, isolation policies and related parameters can be correctly provided on NFs, thus all isolation solutions in the control plane can be effective. For example, the management plane may expect to isolate the resources of applications in S-NSSAI#3 from those in S-NSSAI#4 and S-NSSAI#5, and to correctly configure Network Slice Information (NSI) and S-NSSAI in NFs. This could result in NF service isolation between NFs in S-NSSAI#4 and #5 (in the user plane) and NFs in S-NSSAI#3. Furthermore, even a poorly configured, maliciously compromised slice could affect highly sensitive slices, such as the theft of services / resources and data from mission-critical applications. Figure 5 compared to, Figure 10 Resources are better isolated.
[0171] Some detailed embodiments of this disclosure can be further illustrated below.
[0172] Figure 11 This is a diagram illustrating a process for network slicing deployment and resource isolation according to Embodiment 1 of this disclosure. Figure 11 In this context, IG refers to the quarantine group.
[0173] Some exemplary prerequisites include the following.
[0174] Tenants / vertical consumers have registered with the mobile network operator's (MNO) Business Support System (BSS). Tenant information may include the tenant's industry, restricted areas, regulatory requirements, etc. (The BSS process can be performed by any type of business support system outside the 3GPP scope, but is not limited to this).
[0175] The network slice management service consumer (NSMS_C) representing the tenant or administrator of the MNO has registered with the MNO's Operations Support System (OSS), authenticated with the OSS, and authorized to access NSMS (Annex D is 28.533 V 17.3.0).
[0176] The procedure may include the following steps (also referring to Clauses 7.2 and 7.3 of 28.531 V 18.2.0 and Clause 6 of 28.541 V18.4.0).
[0177] 1. The Network Slice Management Service (NSMS) consumer (NSMS_C) sends a network slice creation request to the NSMS producer (NSMS_P). This request includes a service profile for the slice, security requirements (e.g., SOC 2 / ISO27001 / CC EAL / New 5G NW Security Certification), and a list of other parameters. Application descriptors are included in each service profile. SOC refers to Security Operations Center, ISO refers to International Organization for Standardization, and CC EAL refers to Common Standards Assessment Assurance Level x.
[0178] 2. NSMS_P creates a Network Slice Management Object instance (NS MOI) and a top-level network slice subnet MOI (NSS MOI) for the requested network slice. The service profile is associated with the NS MOI and converted into a slice profile. The top-level NSS MOI is associated with the NSMOI. The converted slice profile is associated with the top-level NSS MOI.
[0179] 3. NSMS_P assigns network slice isolation groups (3.1b) to the top-level NSS MOI and / or NS MOI based on security requirements on the slice, application and / or industry-related regulations for the tenant represented by NSMS_C, and carrier policies. If no matching isolation group exists, NSMS_P creates a new isolation group for the slice (3.1a). Isolation groups (IGs) include: (Refer to S5-234700) Group type, group ID, Group resource isolation rules are a list of the following items: - Resource types (e.g., CP NF, NF related to session management (MGMT), UP NF, exposed NF, radio frequency (RF), subscriber database (DB), N2, N3). - Isolation rules (e.g., dedicated / isolated, shared). - Security standards (e.g., advanced standards such as SOC 2 authentication / EAL 3, or a list of security features such as role-based access control (RBAC), trusted platform modules (TPM), firewalls (FW), web application firewalls (WAF), etc.).
[0180] 3.2a. If no NSS MOI corresponding to the isolation group exists, NSMS_P sends a request to the 5GC and RAN network slice subnet management service producer (NSSMS_P) to create the 5GC NSS MOI and RAN NSS MOI. This request includes multiple slice profiles derived from the top-level NSS MOI associated with the isolation group, the isolation group ID, security criteria, etc.
[0181] 3.3a. The 5GC / RAN NSSMS_P creates (multiple) top-level 5GC / RAN NSS MOIs, associates (multiple) slice profiles with (multiple) NSS MOIs, and sets the isolation group ID and security criteria in (multiple) NSS MOIs. Furthermore, NSSMS_P sets resource sharing indicators in (multiple) NSS MOIs according to the security criteria, and can propagate other sub-NSSs based on requests from NSMS_P and local policies.
[0182] Note: For load balancing and redundancy, NSSMS_P can create more than one 5GC NSS MOI and RAN NSS MOI for an isolation group. 5GC NSSMS_P can assign one or more NSI-Ids to the 5GC NSS MOI according to local policies.
[0183] 3.2b. NSMS_P sends a request to the 5GC and RAN network slice subnet management service producer (NSSMS_P) to update the existing 5GC NSS MOI and RAN NSS MOI corresponding to the isolation group. The request includes slice profiles derived from the top-level NSS MOIs associated with the isolation group, the isolation group ID, and optional security criteria (if required), etc.
[0184] 3.3b. The 5GC / RAN NSSMS_P updates (multiple) top-level 5GC / RAN NSS MOIs, associates (multiple) slice profiles with (multiple) NSS MOIs, and updates the sub-NSSs accordingly (if they exist). If necessary, it can update the security criteria of (multiple) NSS MOIs and update the resource sharing indicators in (multiple) NSS MOIs based on the updated security criteria.
[0185] 4. NSSMS_P converts the service requirements in the slice profile and the security requirements in the security standards into virtualization resource requirements and configuration parameters for 5GC / RANNF.
[0186] 5. NSSMS_P sends a request to the cloud management system to deploy / update virtualized resources for NSS MOI, which is constructed using Virtual Network Functions / Cloud Native Functions (VNF / CNF) and corresponding virtual links.
[0187] 6. After successfully deploying / updating the VNF / CNF of the 5GC / RAN NF service, NSSMS_P sends a request to the Network Function Management Service Producer (NFMS_P) to configure the 5GC / RAN NF based on the Enhanced Network Resource Model (NRM), which takes into account security and isolation requirements.
[0188] 7. NFMS_P is configured accordingly for 5GC / RAN NF based on the enhanced NRM.
[0189] 8. NSSMS_P sends a response to NSMS_P containing NSS information corresponding to (multiple) 5GC / RAN NSSs. Each NSS includes the NSS MOI ID (such as...). Figure 11 The DN (which refers to the proprietary name) and NSI-Id, along with other attributes, are used in this context.
[0190] 9. NSMS_P stores the NSSInfo returned in step 8 in the isolation group and associates (multiple) NSS MOIs with the top-level NSS MOI.
[0191] 10. NSMS_P sends a response to NSMS_C with the ID of the network slice MOI.
[0192] Figure 12 This is a diagram illustrating the process of creating an NSS according to Embodiment 2 of this disclosure.
[0193] As shown in step 3 of Example 1 ( Figure 11 After receiving the NSS creation request from NSMS_P, 5GC / RANNSSMS_P deploys and equips resources / NFs for the network slice isolation group, considering factors such as... Figure 12 The following isolation and security requirements are shown: S1201: The 5GC / RAN NSSMS_P creates (multiple) top-level 5GC / RAN NSS MOIs, associates (multiple) slice profiles with (multiple) NSS MOIs, and sets security criteria and optional network slice isolation group IDs in (multiple) (top-level 5GC / RAN) NSS MOIs. For 5GC, NSSMS_P can assign one or more NSI-Ids to the 5GC NSS MOIs according to local policies.
[0194] S1202: In accordance with security standards, NSSMS_P sets a resource sharing indicator in (multiple) NSS MOIs. The resource sharing indicator indicates whether an NSS MOI shares resources with other NSSs.
[0195] S1203: NSSMS_P checks the resource sharing indicator of the NSS MOI: If the indicator is "shared", then S1203a: S1203a.1 NSSMS_P divides the NSS MOI into two parts. One is a dedicated part, which includes a set of NFs dedicated to the NSS. The other is a shared part, which includes some or all of the NFs shared with other NSSs.
[0196] S1203a.2 If the dedicated section is not empty, NSSMS_P creates a dedicated NSS MOI for that section, populating the dedicated NSI-Id, S-NSSAI, security standards, and performance requirements on the dedicated NSSMOI. Then, the resource sharing indicator of the MOI is set to dedicated.
[0197] S1203a.3 and S1203a.4 If the shared portion is not empty, based on the NSS MOI security standards and the existing NSS isolation group's local policy and security profile, if a matching NSS isolation group exists, NSSMS_P can allocate the NSS isolation group to the shared portion and update the NSS MOI associated with the NSS isolation group. If no matching NSS isolation group exists, NSSMS_P can create a new NSS isolation group to the shared portion, create an NSS MOI, and associate the NSS MOI with the NSS isolation group. NSSMS_P sets the resource sharing indicator in the NSS MOI according to the current NSS MOI's security standards and local policies.
[0198] Note: NSSMS_P can directly create / update matching NSS MOIs for the shared portion without introducing an NSS isolation group.
[0199] If the indicator is "dedicated", then S1203b: S1203b.1 sets the type of NSS MOI to Leaf NSS. S1203b.2 and S1203b.3 deploy VNF / CNF and equip NF for NSS.
[0200] S1203b.31, S1203b.32, if the NF is an NSSF, then the NF is equipped with slice information, which includes S-NSSAI and the corresponding NSI Id supporting each S-NSSAI, and is equipped with NSI information, which includes NSI-Id and the Id of the network slice isolation group associated with each NSI-Id.
[0201] S1203b.33, if the NF is a PCF, then a mapping is configured between the application ID and the S-NSSAI based on the slice profile associated with the NSS MOI. The slice profile will be used to generate UE routing policy (URSP) rules for UEs that support slices.
[0202] Repeat steps S1202 and S1203 until all resources are allocated and configured.
[0203] Example 3 provides NRM enhancements for populating slice isolation-related attributes in network slices, network slice subnets, and 5GC management functions.
[0204] The following new attributes have been added to NRM fragments targeting network slices.
[0205] Network Slicing -> Service Profile:
[0206] Note: Security level is the required state of NRM segments in a network slice.
[0207] Network Slices > Quarantine Groups:
[0208] Network Slicing > Quarantine Groups. Quarantine Profile:
[0209] Note: Security level is understood as a predefined isolation protection level, which specifies the state of security controls and runtime protections that need to be used.
[0210] Note: Security controls used for security protection levels can be dynamic processes and negotiated during runtime. For example, when resources are attacked, additional security controls can be applied to "maintain" the same security level.
[0211] Network slicing subnets:
[0212] Network Slice Subnet > Slice Profile:
[0213] Network slice subnet > Isolation group:
[0214] Network Slicing > Quarantine Groups. Quarantine Profile:
[0215] The following slice-related properties are extended in NRM slices for 5GC NF.
[0216] NSSF features:
[0217] PCF Functions:
[0218] Example 4 is based on the implementation of isolation in the signaling process during the deployment of the new NRM.
[0219] 1. During the mobility and session management signaling process, the NSSF returns the NSI-Id for S-NSSAI to the AMF based on the local configuration provided during the slice deployment process (such as shown in Examples 1 and 2), taking into account security and isolation requirements.
[0220] 2. During the slice replacement process, NSSF selects an alternative S-NSSAI from the appropriate isolation group.
[0221] 3. Configure URSP based on the mapping between the application ID and S-NSSAI provided during the slice deployment process (as shown in Examples 1 and 2).
[0222] 4. When an Application Function (AF) affects the URSP, the PCF should query the NSSF to confirm whether the slice selected by the AF for the application belongs to the same isolation group as the slice(s) obtained from the mapping table based on the application ID.
[0223] 5. If the UE does not comply with the URSP, the NSSF can check whether the slice selected for the Protocol Data Unit (PDU) session belongs to the same isolation group as the slice corresponding to the application in the URSP.
[0224] The above embodiments can be implemented using network and network slice management related products, NSSF and PCF related products to implement network slice resource isolation.
[0225] Figure 13 This is a block diagram illustrating an exemplary structure for a first network node according to an exemplary embodiment of the present disclosure.
[0226] like Figure 13 As shown, the first network node 130 includes a component 1300 configured to: receive a first request from a second network node for creating a network slice, the first request including at least one security requirement; create a network slice management object instance (NS MOI); provide a group for the NS MOI based at least on the at least one security requirement; send a second request to a third network node for at least one network slice subnet management object instance (NSS MOI), the second request including at least the at least one security requirement and an identifier for the group; receive a response from the third network node to the second request, the response including at least one identifier for the at least one NSS MOI; store the at least one identifier for the at least one NSS MOI; and send a response to the first request to the second network node, the response including at least the identifier for the NS MOI.
[0227] In exemplary embodiments of this disclosure, component 1300 is also configured to perform the methods of any of the above embodiments, such as Figure 6 , Figure 11 The method shown.
[0228] In an exemplary embodiment of this disclosure, component 1300 includes: at least one processor 1302; and at least one memory 1304 storing instructions that, when executed by at least one processor 1302, cause execution of a first network node 130.
[0229] Figure 14 This is a block diagram illustrating an exemplary structure for a second network node according to an exemplary embodiment of the present disclosure.
[0230] like Figure 14 As shown, the second network node 140 includes a component 1400 configured to: send a first request to the first network node for the creation of a network slice, the first request including at least one security requirement; and receive a response from the first network node to the first request, the response including at least an identifier of a network slice management object instance NS MOI provided based on at least one security requirement.
[0231] In exemplary embodiments of this disclosure, component 1400 is also configured to perform the methods of any of the above embodiments, such as Figure 7 , Figure 11 The method shown.
[0232] In an exemplary embodiment of this disclosure, component 1400 includes: at least one processor 1402; and at least one memory 1404 storing instructions, which, when executed by at least one processor 1402, cause execution of a second network node 140.
[0233] Figure 15 This is a block diagram illustrating an exemplary structure for a third network node according to an exemplary embodiment of the present disclosure.
[0234] like Figure 15 As shown, the third network node 150 includes a component 1500 configured to: receive a second request from a first network node for at least one NSS MOI, the second request including at least one security requirement; generate the at least one NSS MOI based at least on the second request; generate resource requirements and / or configurations for core network functions and / or radio access network functions associated with the at least one NSS MOI; send the resource requirements and / or configurations to a fourth network node; and send a response to the second request to the first network node, the response including at least one identifier of the at least one NSS MOI.
[0235] In exemplary embodiments of this disclosure, component 1500 is also configured to perform the methods of any of the above embodiments, such as Figure 8A , Figure 8B , Figure 11 , Figure 12 The method shown.
[0236] In an exemplary embodiment of this disclosure, component 1500 includes: at least one processor 1502; and at least one memory 1504 storing instructions that, when executed by at least one processor 1502, cause execution of a third network node 150.
[0237] Figure 16 This is a block diagram illustrating an exemplary structure for a fourth network node according to an exemplary embodiment of the present disclosure.
[0238] like Figure 16 As shown, the fourth network node 160 includes a component 1600 configured to receive resource requests and / or configurations from the third network node. The resource requests and / or configurations are used to configure core network functions and / or radio access network functions associated with at least one NSS MOI.
[0239] In an exemplary embodiment of the present invention, component 1600 is also configured to perform the methods of any of the above embodiments, such as Figure 9 , Figure 11 The method shown.
[0240] In an exemplary embodiment of this disclosure, component 1600 includes: at least one processor 1602; and at least one memory 1604 storing instructions that, when executed by at least one processor 1602, cause execution of a fourth network node 160.
[0241] Processors 1302, 1402, 1502, and 1602 can be any type of processing unit, such as one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), application-specific digital logic, etc. Memory 1304, 1404, 1504, and 1604 can be any type of storage component, such as read-only memory (ROM), random access memory, cache memory, flash memory, optical storage devices, etc.
[0242] Figure 17 This is a block diagram illustrating an apparatus / computer-readable storage medium according to embodiments of the present disclosure.
[0243] like Figure 17As shown, computer-readable storage medium 170 stores instructions 171, which, when executed by at least one processor of a network node (such as a first network node, a second network node, a third network node, or a fourth network node), cause at least one processor of the network node to perform a method according to any of the above embodiments, such as... Figure 6 , Figure 7 , Figure 8A , Figure 8B , Figure 9 , Figure 11 , Figure 12 The method shown.
[0244] Additionally, this disclosure may also provide a carrier containing the computer program / instructions described above. The carrier is one of electronic signals, optical signals, radio signals, or the above computer-readable storage media. Computer-readable storage media may be, for example, optical discs or electronic storage devices such as RAM (Random Access Memory), ROM (Read-Only Memory), flash memory, magnetic tape, CD-ROM, DVD, Blu-ray disc, etc.
[0245] Figure 18 This is a block diagram illustrating an exemplary device unit suitable for performing a method according to an embodiment of the present disclosure for a first network node.
[0246] like Figure 18 As shown, the first network node 180 may include: a receiving unit 1802 configured to receive a first request for network slice creation from a second network node, the first request including at least one security requirement; a creation unit 1804 configured to create a network slice management object instance (NS MOI); a providing unit 1806 configured to provide a group for the NS MOI based on at least one security requirement; a sending unit 1808 configured to send a second request for at least one network slice subnet management object instance (NSS MOI) to a third network node, wherein the second request includes at least one security requirement and an identifier for the group; a receiving unit 1810 configured to receive a response to the second request from the third network node, the response to the second request including at least one identifier of at least one NSS MOI; a storage unit 1812 configured to store at least one identifier of at least one NSS MOI; and a sending unit 1814 configured to send a response to the first request to the second network node, including at least the identifier of the NS MOI.
[0247] In an exemplary embodiment of the present invention, the first network node 170 is also configured to perform the methods of any of the above embodiments, such as... Figure 6 , Figure 11 The method shown.
[0248] Figure 19This is a block diagram illustrating an exemplary device unit suitable for performing a method according to an embodiment of the present disclosure for a second network node.
[0249] like Figure 19 As shown, the second network node 190 may include: a sending unit 1902 configured to send a first request for network slice creation to the first network node, the first request including at least one security requirement; and a receiving unit 1904 configured to receive a response to the first request from the first network node, the response to the first request including at least an identifier of a network slice management object instance NS MOI provided based on at least one security requirement.
[0250] In an exemplary embodiment of the present invention, the second network node 190 is also configured to perform the methods of any of the above embodiments, such as Figure 7 , Figure 11 The method shown.
[0251] Figure 20 This is a block diagram illustrating an exemplary device unit suitable for performing a method according to an embodiment of the present disclosure for a third network node.
[0252] like Figure 20 As shown, the third network node 200 may include: a receiving unit 2002 configured to receive a second request for at least one NSS MOI from a first network node, wherein the second request includes at least one security requirement; a generating unit 2004 configured to generate at least one NSS MOI based at least on the second request; a generating unit 2006 configured to generate resource requirements and / or configurations for core network functions and / or radio access network functions associated with at least one NSS MOI; a sending unit 2008 configured to send the resource requirements and / or configurations to a fourth network node; and a sending unit 2010 configured to send a response to the second request to the first network node, the response to the second request including at least one identifier of at least one NSS MOI.
[0253] In an exemplary embodiment of the present invention, the third network node 200 is also configured to perform the methods of any of the above embodiments, such as... Figure 8A , Figure 8B , Figure 11 , Figure 12 The method shown.
[0254] Figure 21 This is a block diagram illustrating an exemplary device unit suitable for performing a method according to an embodiment of the present disclosure for a fourth network node.
[0255] like Figure 21As shown, the fourth network node 210 may include a receiving unit 2102 configured to receive resource requests and / or configurations from the third network node. The resource requests and / or configurations are used to configure core network functions and / or radio access network functions associated with at least one NSS MOI.
[0256] In an exemplary embodiment of the present invention, the fourth network node 210 is also configured to perform the methods of any of the above embodiments, such as Figure 9 , Figure 11 The method shown.
[0257] The term 'unit' may have a conventional meaning in the field of electronic, electrical and / or electronic equipment, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, outputs and / or display functions, such as those described herein.
[0258] As used in this disclosure, the term "circuit" may refer to one or more or all of the following: (a) Hardware circuit implementation only (e.g., implemented with purely analog and / or digital circuits) and (b) A combination of hardware circuitry and software, such as (if applicable): (i) A combination of (multiple) analog and / or digital hardware circuits and software / firmware, and (ii) Any part of a hardware processor having software (including (multiple) digital signal processors, software, and (multiple) memories, which work together to enable a device (such as a mobile phone or server) to perform various functions) and (c) The operation requires software (e.g., firmware) for the operation of (multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or parts thereof, but the software may be absent when the operation does not require the software.
[0259] This definition of "circuit" applies to all uses of the term in this application. As a further example, as used in this application, the term "circuit" also covers only hardware circuitry or processors (or processors), or portions of hardware circuitry or servers and their accompanying software and / or firmware implementations. For example, where applicable to certain claim elements, the term "circuit" also covers baseband integrated circuits or processor integrated circuits for mobile devices or similar integrated circuits in servers, cellular network devices, or other computing or networking devices.
[0260] Using these units, the device can be configured with any type of computing and storage resources from at least one network node / device / entity / device associated with the communication system, without requiring a fixed processor or memory. Virtualization and network computing technologies (e.g., cloud computing) can be further introduced to improve the efficiency of network resource utilization and network flexibility.
[0261] The techniques described herein can be implemented through various components, such that the means for implementing one or more functions of the corresponding apparatus described in the embodiments includes not only prior art components but also components for implementing one or more functions of the corresponding apparatus described in the embodiments, and it can include separate components for each individual function, or components that can be configured to perform two or more functions. For example, these techniques can be implemented in hardware (one or more devices), firmware (one or more devices), software (one or more modules / units), or a combination thereof. For firmware or software, implementation can be performed by modules (e.g., procedures, functions, etc.) that perform the functions described herein.
[0262] In some embodiments, some or all of the functions described herein may be provided by processing circuitry that executes instructions stored in memory, which in some embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functions may be provided by processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether or not instructions stored on a non-transitory computer-readable storage medium are executed, the processing circuitry may be configured to perform the described functions. The benefits provided by such functions are not limited to individual processing circuitry or other components of the computing device, but are enjoyed in general by the computing device and / or by the end user and wireless network.
[0263] As used herein, the term “non-transitory” refers to the limitation of the medium itself (i.e., tangible, not signaling), rather than a limitation on the persistence of data storage (e.g., RAM versus ROM).
[0264] As described in the exemplary embodiments above in this disclosure, the embodiments herein offer numerous advantages. According to embodiments of this disclosure, exemplary embodiments propose a mechanism that allows for the determination of at least one NSS MOI in response to a request for the creation of a network slice that includes at least one security requirement. Isolation requirements for resources, particularly isolation requirements for network functions (NFs) defined in at least one NSS MOI, can be defined as satisfying at least one security requirement.
[0265] Therefore, interactions between NFs belonging to different isolation groups can be restricted, UE signaling messages can be routed to the correct control plane (CP) NF, and UE data services can be routed to the correct user plane function (UPF) without compromising isolation requirements.
[0266] It should be understood that the above embodiments are for illustrative purposes only and not for limitation. This disclosure may be practiced in other ways than those specifically set forth herein without departing from its essential characteristics. All changes to these embodiments without departing from the meaning of the appended claims and their equivalents are intended to be included herein.
[0267] References The following are references incorporated in their entirety into this paper: 3GPP TR 28.811 V17.0.0 3GPP TS 28.530 V17.4.0 3GPP TS 28.533 V17.3.0 3GPP TS 28.531 V18.2.0 3GPP TS 28.541 V18.4.0 3GPP TS 23.501 V18.2.0 S5-234700, Adding NRM for Network Slice Isolation, 3GPP TSG-SA5 Meeting #149, Berlin, Germany, May 22-26, 2023 WO2021 / 159461 Abbreviation Explanation CNF containerized network functionality MnSM Management Service MOIM Management Object Instance NFMS_P Network Function Management Service Producer NSMS_P Network Slice Management Service Producer NSSMS_P Network Slicing Subnet Management Service Producer NRM Network Resource Model NSCN network service consumers NSPN network service provider NS network slices NSSN network slice subnet VNF Virtual Network Function S-NSSAI Single Network Slice Selection Auxiliary Information NSI network slicing example
Claims
1. A method (600) executed by a first network node, comprising: Receive (S602) a first request for the creation of a network slice from the second network node, the first request including at least one security requirement; Create a (S604) Network Slice Management Object instance NS MOI; Based on at least one of the security requirements, provide (S606) a group for the NS MOI; Send (S608) a second request to a third network node for at least one Network Slice Subnet Management Object Instance (NSS MOI), wherein the second request includes at least: the at least one security requirement and the identifier of the group; Receive (S610) a response to the second request from the third network node, the response to the second request including at least one identifier of the at least one NSS MOI; Store (S612) the at least one identifier of the at least one NSS MOI; and Send (S614) a response to the first request to the second network node, the response to the first request including at least the identifier of the NS MOI.
2. The method (600) according to claim 1, The at least one NSS MOI mentioned above includes: At least one core network slice subnet management object instance (CN NSSMOI), and / or at least one radio access network slice subnet management object instance (RAN NSSMOI); The first network node also creates a root network slice subnet management object instance NSS MOI; The groups mentioned include isolated groups or shared groups; and The group is also provided for the root NSS MOI.
3. The method (600) according to claim 2, Where no matching group exists for the NS MOI and / or the root NSS MOI, the group is created by the first network node, and the at least one CN NSS MOI and / or the at least one RAN NSS MOI is created by the third network node; or When a matching group exists for the NS MOI and / or the root NSS MOI, the group is assigned by the first network node, and the at least one CN NSS MOI and / or the at least one RAN NSS MOI is updated by the third network node.
4. The method (600) according to claim 2 or claim 3, The first request also includes a list of service profiles, where each service profile includes an application descriptor; and The at least one security requirement mentioned therein includes a list of security levels or security features.
5. The method (600) according to any one of claims 2 to 4, The group includes an isolation profile based on at least one of the security requirements; The isolation profile mentioned therein includes group resource isolation rules; The group resource isolation rules mentioned above include at least: resource type, isolation rules, and / or security standards; The resource type mentioned above includes at least one of the following: network function type, network function, database, or communication interface; and The security standards mentioned therein include a list of security levels or security features.
6. The method (600) according to any one of claims 2 to 5, The first network node also provides the group based on regulations and operator policies.
7. The method (600) according to any one of claims 2 to 6, The second request also includes at least one slice profile for the at least one CN NSS MOI and / or the at least one RAN NSS MOI.
8. The method (600) according to any one of claims 1 to 7, The first network node includes: Network slice management service producer NSMS_P; The second network node includes: a network slice management service consumer NSMS_C; and The third network node mentioned above includes: the network slice subnet management service producer NSSMS_P.
9. A method (700) executed by a second network node, Send (S702) a first request for network slice creation to the first network node, the first request including at least one security requirement; and Receive (S704) a response to the first request from the first network node, the response including at least an identifier of a network slice management object instance NS MOI provided based on at least one security requirement.
10. The method (700) according to claim 9, The first request created for network slices also includes an application descriptor; The response to the first request is also provided based on the application descriptor; The first network node includes: a network slice management service producer NSMS_P; and The second network node includes: Network Slice Management Service Consumer NSMS_C.
11. A method (800) performed by a third network node, comprising: Receive (S802) a second request for at least one NSS MOI from the first network node, wherein the second request includes at least one security requirement; At least one NSS MOI is generated based on the second request (S804); Generate (S806) resource requirements and / or configurations for core network functions and / or radio access network functions related to the at least one NSS MOI; Send the resource requirements and / or configuration (S808) to the fourth network node; and Send (S810) a response to the second request to the first network node, the response including at least one identifier of the at least one NSS MOI.
12. The method (800) according to claim 11, The at least one NSS MOI mentioned above includes: At least one CN NSS MOI and / or at least one RAN NSS MOI; and The second request further includes: a group identifier, and at least one slice profile, each slice profile including at least one application descriptor.
13. The method (800) according to claim 12, The third network node sets security criteria and optional identifiers for network slice groups in at least one CNNSS MOI and / or at least one RAN NSS MOI, based at least on the second request; and The third network node assigns one or more identifiers of the network slice instance NSI to the CN NSS MOI for the fifth generation core network 5GC based on at least a local policy.
14. The method (800) according to claim 12 or claim 13, Generating at least one CN NSS MOI and / or at least one RAN NSS MOI includes: Create (S812) root CN NSS MOI and / or root RAN NSS MOI; For the dedicated resources of the root CN NSS MOI and / or the root RAN NSS MOI, create (S814) a dedicated CN NSS MOI and / or a dedicated RAN NSS MOI; as well as For the shared resources of the root CN NSS MOI and / or the root RAN NSS MOI, create (S814) a shared CN NSS MOI and / or a shared RAN NSS MOI, wherein the shared CN NSS MOI and / or the shared RAN NSS MOI has an NSS group, or the shared CN NSS MOI and / or the shared RAN NSS MOI has an NSS group but does not have the NSS group.
15. The method (800) according to any one of claims 12 to 14, Generating the at least one CN NSS MOI and / or at least one RAN NSS MOI further includes: For the dedicated CN NSS MOI and / or the dedicated RAN NSS MOI, or for the shared CN NSS MOI and / or the shared RAN NSS MOI, set a resource sharing indicator (S818).
16. The method (800) according to any one of claims 12 to 14, The third network node sets the first resource sharing indicator in the NSS MOI; When the first resource sharing indicator indicates that the NSS MOI is shared, the third network node divides the NSS MOI into a dedicated part and a shared part; When the dedicated portion is not empty, the third network creates a dedicated NSS MOI for the dedicated portion; and When the shared portion is not empty, the third network creates / updates a matching NSS MOI for the shared portion, wherein the matching NSS MOI has an NSS group, or the matching NSS MOI does not have the NSS group; and sets a second resource sharing indicator in the matching NSS MOI at least based on security standards and local policies.
17. The method (800) according to any one of claims 16, When the first resource sharing indicator indicates that the NSS MOI is dedicated, the third network node sets the type of the NSS MOI to leaf NSS.
18. The method (800) according to any one of claims 12 to 17, The resource requirements and / or configurations mentioned above include slice information and network slice instance (NSI) information, used to configure the network slice selection function (NSSF); and / or The resource requirements and / or configurations mentioned therein include a mapping between at least one identifier of the application and at least one Single Network Slice Selection Auxiliary Information (S-NSSAI) for configuring the Policy Control Function (PCF).
19. The method (800) according to claim 18, The slice information includes network slice selection assistance information S-NSSAI and the corresponding identifier of the NSI supporting each S-NSSAI. The NSI information includes at least one identifier of the NSI and at least one identifier of the network slice isolation group associated with the at least one identifier of the NSI.
20. The method (800) according to claim 18 or claim 19, The at least one S-NSSAI is based on at least one slice profile associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI; and The at least one S-NSSAI is used to generate User Equipment Routing Policy URSP rules for User Equipment (UE), and the UE supports slices associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI.
21. The method (800) according to any one of claims 12 to 20, The at least one security requirement mentioned therein includes a list of security levels or security features.
22. The method (800) according to any one of claims 12 to 21, The group mentioned above includes an isolation profile; The isolation profile mentioned therein includes group resource isolation rules; The group resource isolation rules mentioned therein include at least: resource type, isolation rules, and security standards; The resource type mentioned above includes at least one of the following: network function type, network function, database, or communication interface; and The security standards mentioned therein include a list of security levels or security features.
23. The method (800) according to any one of claims 11 to 22, The first network node includes: Network slice management service producer NSMS_P; The third network node includes: the network slice subnet management service producer NSSMS_P; and The fourth network node includes at least one of the following: Network Function Management Service Producer (NFMS_P), Cloud Infrastructure, Network Slice Selection Function (NSSF), or Policy Control Function (PCF).
24. A method (900) executed by a fourth network node, Receive resource requests and / or configurations from the third network node (S902); The resource requirements and / or configurations mentioned therein are used to configure core network functions and / or radio access network functions associated with at least one NSS MOI.
25. The method (900) according to claim 24, The at least one NSS MOI mentioned above includes: At least one CN NSS MOI and / or at least one RAN NSS MOI.
26. The method (900) according to claim 25, The resource requirements and / or configurations mentioned therein include: Slice information and network slice instance (NSI) information are used to configure the network slice selection function (NSSF).
27. The method (900) according to claim 26, The slice information includes network slice selection assistance information S-NSSAI and the corresponding identifier of the NSI supporting each S-NSSAI. The NSI information includes at least one identifier of the NSI and at least one identifier of the network slice isolation group associated with the at least one identifier of the NSI.
28. The method (900) according to claim 27, During the mobility and session management signaling process, the NSSF sends at least one identifier of the NSI for the S-NSSAI to the Access and Mobility Management Function (AMF), based at least on the S-NSSAI and the corresponding identifier of the NSI supporting each S-NSSAI; or During the slice replacement process, the NSSF selects a candidate S-NSSAI based on the isolation group associated with the corresponding identifier of the S-NSSAI and the NSI supporting each S-NSSAI; or The NSSF check determines whether the slice selected by the application function AF or user equipment UE for the application is in the same group defined in the user equipment routing policy URSP associated with the application.
29. The method (900) according to claim 25, The resource requirements and / or configurations mentioned therein include: A mapping between at least one identifier of the application and at least one single network slice selection auxiliary information S-NSSAI is used to configure the policy control function PCF.
30. The method (900) according to claim 29, The at least one S-NSSAI is based on at least one slice profile associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI; and The at least one S-NSSAI is used to generate User Equipment Routing Policy URSP rules for User Equipment (UE), and the UE supports slices associated with the at least one CN NSS MOI and / or at least one RAN NSS MOI.
31. The method (900) according to claim 30, The PCF determines whether the slices selected by the application in the User Equipment Routing Policy (URSP) are in the same group.
32. The method (900) according to any one of claims 24 to 31, The third network node includes: Network slicing subnet management service producer NSSMS_P; and The fourth network node includes at least one of the following: Network Function Management Service Producer (NFMS_P), Cloud Infrastructure, Network Slice Selection Function (NSSF), or Policy Control Function (PCF).
33. A first network node (130) including a component (1300) configured to: Receive a first request for the creation of a network slice from a second network node, the first request including at least one security requirement; Create a network slice management object instance NS MOI; A group for the NS MOI shall be provided based on at least one of the aforementioned security requirements; Send a second request to a third network node for at least one Network Slice Subnet Management Object Instance (NSS MOI), wherein the second request includes at least: the at least one security requirement and the identifier of the group; Receive a response to the second request from the third network node, the response to the second request including at least one identifier of the at least one NSS MOI; The at least one identifier storing the at least one NSS MOI; and Send a response to the first request to the second network node, wherein the response to the first request includes at least the identifier of the NS MOI.
34. The first network node (130) according to claim 33, wherein the component (1300) is further configured to perform the method according to any one of claims 2 to 8.
35. The first network node (130) according to claim 33 or claim 34, wherein the component (1300) comprises: At least one processor (1302); as well as At least one memory (1304) stores instructions that, when executed by the at least one processor (1302), cause the execution of the first network node (130).
36. A second network node (140) comprising a component (1400) configured to: A first request for network slice creation is sent to a first network node, the first request including at least one of the following: security requirements and an application descriptor; and The response to the first request is received from the first network node, the response including at least an identifier of a network slice management object instance (NS MOI), the identifier of the network slice management object instance (NS MOI) being provided based on at least one of the security requirement and the application descriptor.
37. The second network node (140) of claim 36, wherein the component (1400) is further configured to perform the method of claim 10.
38. The second network node (140) according to claim 36 or claim 37, wherein the component (1400) comprises: At least one processor (1402); as well as At least one memory (14044) stores instructions that, when executed by the at least one processor (1402), cause the execution of the second network node (140).
39. A third network node (150) comprising a component (1500) configured to: Receive a second request for at least one NSS MOI from a first network node, wherein the second request includes at least: At least one security requirement; The at least one NSS MOI is generated based on at least the second request; Generate resource requirements and / or configurations for core network functions and / or radio access network functions related to the at least one NSS MOI; Send the resource requirements and / or configuration to the fourth network node; as well as Send a response to the second request to the first network node, the response including at least one identifier of the at least one NSSMOI.
40. The third network node (150) according to claim 39, wherein the component is further configured to perform the method according to any one of claims 12 to 23.
41. The third network node (150) according to claim 39 or claim 40, wherein the component (1500) comprises: At least one processor (1502); as well as At least one memory (1504) stores instructions that, when executed by the at least one processor (1502), cause the execution of the third network node (150).
42. A fourth network node (160) comprising a component (1600) configured to: Receive resource requests and / or configurations from a third network node; The resource requirements and / or configurations mentioned therein are used to configure core network functions and / or radio access network functions associated with at least one NSS MOI.
43. The fourth network node (160) according to claim 42, wherein the component (1600) is further configured to perform the method according to any one of claims 25 to 32.
44. The fourth network node (160) according to claim 42 or claim 43, wherein the component (1600) comprises: At least one processor (1602); as well as At least one memory (1604) stores instructions that, when executed by the at least one processor (1602), cause the execution of the fourth network node.
45. A computer-readable storage medium (170) storing instructions (171) that, when executed by at least one processor of a network node, cause the at least one processor of the network node to perform the method according to any one of claims 1 to 32.
Citation Information
Patent Citations
Automated regeneration of low quality content to high quality content
WO2021015946A1
Method for network slice isolation management
WO2021159461A1