Network system including a 5G specialized network, and end-to-end network slicing method performed in the corresponding system
The end-to-end network slicing method addresses the challenge of maintaining zero-trust security in 5G networks by using NSI information and virtual routers to securely route data packets from terminals to service servers, achieving enhanced security and cost efficiency.
Patent Information
- Application Number
- JP2024197750
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2024-08-22
- Filing Date
- 2024-11-12
- Publication Date
- 2025-06-23
- Estimated Expiration
- 2044-11-12
AI Technical Summary
Existing 5G network systems face challenges in maintaining end-to-end zero-trust security, particularly when communicating through public Internet networks between the 5G core and the service server.
An end-to-end network slicing method is implemented, where a controller authenticates terminals and transmits Network Slicing Index (NSI) information, and a service gateway processes GTP header and NSI information to route data packets through virtual routers, ensuring secure communication from terminals to service servers.
This solution enables end-to-end zero-trust security across different network types, enhancing security by logically separating terminal and server communications, while reducing costs compared to constructing physically independent networks.
Smart Images

Figure 0007696666000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a network system including a 5G specialized network and an end-to-end network slicing method performed in the corresponding system. More specifically, the terminal communicates with the 5G core via a first network, and the 5G core communicates with the service server via a second network different from the first network. A service gateway is located at the end of the second network. In a network system including a 5G specialized network, the present invention relates to an end-to-end network slicing method capable of implementing end-to-end zero-trust security from the terminal to the service server.
Background Art
[0002] Zero trust is a cybersecurity model based on the premise of "trust nothing". It is a concept that basically verifies not only external connectors but also users connected internally without unconditional trust. That is, when a user or device requests access, a thorough verification is performed, and even if the verification is made, only a minimum level of trust is given to allow access.
[0003] The term zero trust was proposed by John Kindervag, a cybersecurity expert in 2010 and the chief researcher of Forrester Research. In May 2020, NIST (National Institute of Standards and Technology, USA) established some technologies through the Zero Trust Architecture Technical Report (800-207), and the concept of granular boundary security was materialized beyond the simple horizontal same-movement boundary for internal and external or the same network.
[0004] More specifically, the zero-trust basic model does not consider the entire system as a large monolithic block to be protected all at once. Instead, it divides every part into micro segmentation elements and applies security to each element using a granular perimeter enforcement approach as its core.
[0005] Therefore, in the recent trend where a number of security-related technologies related to 5G specialized networks are being studied, in a network system that includes a 5G specialized network and uses two or more different networks, a technology in which the zero-trust security is fully realized is required. As a related prior art, there is a security technology that utilizes VPN technology in a 5G network, such as Korean Registered Patent No. 10-2512037. However, in such a technology, although security can be maintained from the terminal to the core, there is a problem that security cannot be maintained when communicating through the public Internet between the core and the destination (in the present invention, the service server).
[0006] Therefore, there is a need for an end-to-end zero-trust security technology that maintains security from the terminal to the service server while enabling each of a plurality of terminals and a plurality of service servers to communicate in a logically separated network.
Prior Art Documents
Patent Documents
[0007]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0008] The present invention relates to a network system including a 5G specialized network and an end-to-end network slicing method performed in the system. More specifically, the terminal communicates with the 5G core via a first network, and the 5G core communicates with the service server via a second network different from the first network. A service gateway is located at the end of the second network. An object of the present invention is to provide an end-to-end network slicing method capable of implementing end-to-end zero-trust security from the terminal to the service server in a network system including a 5G specialized network.
Means for Solving the Problems
[0009] In order to solve the above problems, in one embodiment of the present invention, there is provided an end-to-end network slicing method performed in a network system including a 5G specialized network. The network system includes a 5G core, a service gateway, and a controller. The controller performs an NSI information transmission step of authenticating a terminal and transmitting NSI information including an NSI (Network Slicing Index) requested by the terminal to the corresponding terminal, a VR information transmission step of transmitting, by the controller, VR information including terminal information for the authenticated terminal and VR matching information related to a virtual router determined by the NSI to the service gateway, a data reception step of receiving, by the service gateway, a data packet including GTP header information, NSI information, and a payload from the authenticated terminal, and a data transmission step of transmitting, by the service gateway, the data packet in which the GTP header information and the NSI information are processed through the virtual router determined based on the VR information to the service server. The terminal and the 5G core communicate with each other via a first network located between the terminal and the 5G core, the 5G core and the service gateway communicate with each other via a second network located between the 5G core and the service gateway, and the first network and the second network provide a network slicing method corresponding to different networks from each other.
[0010] The service gateway generates a plurality of virtual routers so that each of the plurality of terminals and the plurality of service servers can communicate, and the virtual routers used for communication between different terminals and different service servers are different from each other, so that the communication between each of the plurality of terminals and the plurality of service servers is logically separated from each other.
[0011] The NSI information transmission step includes a terminal information reception step of receiving terminal information from a terminal, and a terminal authentication step of authenticating the corresponding terminal based on the received terminal information. After the authentication of the corresponding terminal is completed, the NSI information is transmitted to the corresponding terminal together with the authentication result information indicating that the corresponding terminal has been authenticated.
[0012] The data transmission step includes a GTP header information processing step of processing GTP header information with the received data packet by a service gateway, and an NSI information processing step of processing NSI information with the data packet for which the GTP header information has been processed by the service gateway, and transmitting the data packet for which the GTP header information and the NSI information have been processed to an input port of a virtual router determined by any one of a plurality of virtual routers based on the VR information.
[0013] The service gateway includes a first port corresponding to a physical interface. The GTP header information processing step transmits a first intermediate data packet obtained by removing GTP header information from the data packet transmitted via the first port to an NSI information processing unit of the service gateway, and transmits the first intermediate data packet via a GPRS tunnel corresponding to the removed GTP header information.
[0014] The service gateway includes a second port and a third port corresponding to a virtual interface. The second port corresponds to the input port of the virtual router, and the third port corresponds to the output port of the virtual router. After receiving a first intermediate data packet with GTP header information removed from the data packet, the NSI information processing step removes NSI information from the first intermediate data packet and transmits a second intermediate data packet to the VR part of the service gateway. The second intermediate data packet is transmitted to the second port of the virtual router corresponding to the removed NSI information. The second port to which the second intermediate data packet is transmitted is determined based on VR matching information including information on the second port determined by the NSI information.
[0015] To solve the above problems, the present invention provides a network system including a 5G specialized network that performs an end-to-end network slicing method. The network system includes a 5G core, a service gateway, and a controller. The controller performs an NSI information transmission step of authenticating a terminal and transmitting NSI information including an NSI (Network Slicing Index) requested by the terminal to the corresponding terminal, and a VR information transmission step of transmitting VR information including terminal information for the authenticated terminal and VR matching information related to a virtual router determined by the NSI to the service gateway. The service gateway performs a data reception step of receiving a data packet including GTP header information, NSI information, and a payload from the authenticated terminal, and a data transmission step of transmitting the data packet in which the GTP header information and the NSI information are processed to a service server through the virtual router determined based on the VR information. The terminal and the 5G core communicate with each other via a first network located between the terminal and the 5G core, and the 5G core and the service gateway communicate with each other via a second network located between the 5G core and the service gateway. The first network and the second network provide a network system corresponding to different networks from each other.
Advantages of the Invention
[0016] According to the present invention, even in a network system that uses two types of networks with different network operation countries or operators, end-to-end zero-trust security can be implemented from the terminal to the server.
[0017] Further, according to the present invention, by configuring independent networks for each terminal, service, and server, it is possible to control and manage network access, thereby enhancing security.
[0018] Furthermore, according to the present invention, by forming a logically segmented network, security can be enhanced and costs can be reduced compared to constructing a physically independent network.
[0019] Also, according to the present invention, since each of a plurality of terminals operates in an independent network, even if one terminal is hacked, damage to the remaining terminals can be minimized.
Brief Description of the Drawings
[0020]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
DETAILED DESCRIPTION OF THE INVENTION
[0021] Hereinafter, various embodiments and / or aspects will be described with reference to the drawings. In the following description, for the purpose of explanation, a number of specific details are disclosed to assist in a general understanding of one or more aspects. However, it will also be recognized by those of ordinary skill in the art of the present invention that these aspects can be practiced without such specific details. The following description and the accompanying drawings detail specific exemplary aspects of one or more aspects. However, such aspects are exemplary, and some of the various methods in accordance with the principles of the various aspects are available, and the description is intended to cover all such aspects and their equivalents.
[0022] Also, various aspects and features are presented by a system including a number of devices, components, and / or modules, etc. It should be understood and recognized that various systems can include additional devices, components, and / or modules, etc., and / or can also not include all of the devices, components, modules, etc. discussed in relation to the drawings.
[0023] As used herein, terms such as "embodiment", "example", "aspect", "exemplification", etc. do not necessarily imply that any described aspect or design is better or has advantages over other aspects or designs. Terms such as "part", "component", "module", "system", "interface", etc. used hereinafter generally refer to computer-related entities, e.g., hardware, a combination of hardware and software, software.
[0024] Also, the terms "comprising" and / or "including" are to be understood as meaning that the recited feature and / or component exists, but do not preclude the presence or addition of one or more other features, components and / or groups thereof.
[0025] Also, terms including ordinal numbers such as first, second, etc. are used to describe various components, but the components are not limited by such terms. The terms are used only for the purpose of distinguishing one component from another. For example, without departing from the scope of the present invention, a first component may be referred to as a second component, and similarly, a second component may be referred to as a first component. The term "and / or" includes any combination of a plurality of relatedly described items or any of the plurality of relatedly described items.
[0026] Also, in the embodiments of the present invention, unless otherwise defined, technical and scientific terms are included, and all terms used herein have the same meaning as is generally understood by those of ordinary skill in the technical field to which the present invention pertains. Terms defined in commonly used dictionaries should be construed to have a meaning consistent with the meaning in the context of the related art, and should not be construed in an idealized or overly formal sense unless explicitly defined in the embodiments of the present invention.
[0027] The "terminal" mentioned below is embodied by a computer or a mobile terminal device that can connect to a server and other terminals via a network, or corresponds to a computing device that performs the corresponding functions. Here, the computer includes, for example, a notebook computer, a desktop, a laptop, etc. on which a web browser is installed. The mobile terminal device is, for example, a wireless communication device that guarantees portability and mobility, including all types of handheld-based wireless communication devices such as smartphones, PCS (Personal Communication System), GSM (Global System for Mobile communications), PDC (Personal Digital Cellular), PHS (Personal Handy phone System), PDA (Personal Digital Assistant), IMT (International Mobile Telecommunication)-2000, CDMA (Code Division Multiple Access)-2000, W-CDMA (W-Code Division Multiple Access), Wibro (Wireless Broadband Internet), BLE beacon (Bluetooth Low Energy Beacon) terminals, etc. Also, the "network" is embodied by all types of wired networks such as a local area network (LAN), a wide area network (WAN), or a value-added network (VAN), a mobile radio communication network, or a satellite communication network, etc.
[0028] FIG. 1 is a diagram schematically showing the configuration of a network system that includes a 5G specialized network according to an embodiment of the present invention and performs an end-to-end network slicing method.
[0029] As shown in FIG. 1, a network system including a 5G specialized network that performs an end-to-end network slicing method, the network system including a 5G core 200, a service gateway 300, and a controller 400. The controller 400 authenticates the terminal 100 and transmits NSI information including the NSI (Network Slicing Index) requested from the terminal 100 to the corresponding terminal 100 in an NSI information transmission step. The controller 400 transmits VR information including terminal information for the authenticated terminal 100 and VR matching information related to a virtual router determined by the NSI to the service gateway 300 in a VR information transmission step. The service gateway 300 receives a data packet including GTP header information, NSI information, and a payload from the authenticated terminal 100 in a data reception step. The service gateway 300 transmits the data packet in which the GTP header information and the NSI information are processed via the virtual router determined based on the VR information to the service server 500 in a data transmission step. The terminal 100 and the 5G core 200 communicate via a first network located between the terminal 100 and the 5G core 200. The 5G core 200 and the service gateway 300 communicate via a second network located between the 5G core 200 and the service gateway 300. The first network and the second network correspond to different networks from each other.
[0030] Specifically, as shown in FIG. 1, in the network system of the present invention, a plurality of terminals 100 (1 to 100.N, hereinafter referred to as 100, where N is a natural number of 1 or more) communicate with the 5G core 200 via a first network, and the 5G core 200 communicates with the service server 500 via a second network. The operating country or operating entity of the first network and the second network are different from each other. Here, preferably, the configuration from the terminal 100 to the 5G core 200, that is, part A in FIG. 1, corresponds to a 5G specialized network or a 5G private network. Although not shown in FIG. 1, referring to FIG. 2, the network system further includes components for implementing a 5G specialized network, such as RU, DU, and CU. The RU, DU, and CU are preferably located between the terminal 100 and the 5G core 200. A more specific description of the RU, DU, and CU will be described later with reference to FIG. 2.
[0031] As shown in FIG. 1, in part B of FIG. 1, that is, in the configuration from the 5G core 200 to a plurality of service servers (500.1 to 500.N, hereinafter referred to as 500), it includes a service gateway 300. The service gateway 300 and the 5G core 200 communicate via a second network. Here, as an embodiment of the present invention, the second network preferably corresponds to a public Internet network. However, according to other embodiments of the present invention, it can correspond to a network having an operating country or operating entity different from that of the first network. Also, the configuration shown in part B of FIG. 1 further includes a controller 400, and the controller 400 functions to control the service gateway 300.
[0032] A network system that performs the end-to-end network slicing method of the present invention is characterized in that each of N terminals 100 and N service servers 500 communicates independently with each other. For example, in FIG. 1, when terminal #1 (100.1) communicates with service server #1 (500.1) and terminal #2 (100.2) communicates with service server #2 (500.2), both terminal #1 (100.1) and terminal #2 (100.2) communicate with service server #1 (500.1) and service server #2 (500.2) via the first network and the second network. However, the communication between terminal #1 (100.1) - service server #1 (500.1) and the communication between terminal #2 (100.2) - service server #2 (500.2), that is, the communication per terminal, are logically separated from each other.
[0033] In the case of the conventional network separation technology, only for the part from the terminal 100 to the 5G core 200, that is, for part A, known technologies (such as VPN (Virtual Private Network)) are used to separate the communications of each of the plurality of terminals 100. However, in such a case, there is a problem that the security is weakened for the communication after the 5G core 200.
[0034] For example, when the head office with a server is located in the country and there is a factory overseas, a specialized network service can be constructed in the factory to maintain the security in the factory. However, when the factory and the head office communicate, it is costly to construct another private network or specialized network, and the public Internet network is often used. In such a case, a problem occurs in that security weaknesses become apparent in the communication between the head office and the factory.
[0035] In order to solve such problems, the inventor of the present invention has constructed a service gateway 300 that generates a plurality of virtual routers (VRs) between the 5G core 200 and the server 500, so that the respective communications of the plurality of terminals 100 and the plurality of servers 500 are performed via different virtual routers, thus leading to the construction of a completely separated network service from the terminal 100 to the server 500.
[0036] More specifically, the end-to-end network slicing method of the present invention includes an NSI information transmission step in which the controller 400 authenticates the terminal 100 and transmits NSI information including the NSI (Network Slicing Index) requested from the terminal 100 to the corresponding terminal 100, and a VR information transmission step in which the controller 400 transmits VR information including terminal information for the authenticated terminal 100 and VR matching information related to the virtual router determined by the NSI to the service gateway 300, a data reception step in which the service gateway 300 receives a data packet including GTP header information, NSI information, and a payload from the authenticated terminal 100, and a data transmission step in which the service gateway 300 transmits the data packet in which the GTP header information and the NSI information are processed to the service server 500 via the virtual router determined based on the VR information.
[0037] First, the terminal 100 that intends to communicate with the service server 500 transmits its own terminal information to the controller 400. Here, referring to FIG. 1, it is desirable that the terminal information be passed along the route of terminal 100 → the first network → 5G core 200 → the second network → service gateway 300 → controller 400. Also, when the terminal 100 transmits its own terminal information to the controller 400, it requests the NSI from the controller 400. A more detailed description of the NSI will be given later in the description regarding FIGS. 4 and 7.
[0038] The controller 400 that has received the terminal information and the NSI request from the terminal 100 authenticates the corresponding terminal 100 based on the terminal information. When the authentication for the corresponding terminal 100 is completed, the controller 400 performs an NSI information transmission step of transmitting authentication result information indicating that the authentication is completed and NSI information including the requested NSI to the terminal 100.
[0039] Thereafter, the terminal 100 that has received the authentication result information puts the data to be sent to the service server 500 into data packets and transmits them to the service server 500. The service gateway 300 performs a data reception step of receiving the data packets transmitted by the terminal 100. Here, the data packets include GTP header information, NSI information received from the controller 400, and a payload, and the data that the terminal 100 sends to the service server 500 is included in the payload.
[0040] On the other hand, after transmitting the authentication result information and the NSI information to the terminal 100, the controller 400 performs a VR information transmission step of transmitting the terminal information for the authenticated terminal 100 and VR (Virtual Router) information to the service gateway 300. The VR information includes VR matching information related to the virtual router determined by the NSI. That is, the data packet is transmitted to the virtual router determined based on the NSI information included in the data packet, and the data that the terminal 100 intends to send to the service server 500 is transmitted to the service server 500 via the virtual router.
[0041] More specifically, the service gateway 300 performs a data transmission step of transmitting the data included in the data packet received from the terminal 100 to the service server 500. Without directly transmitting the data packet to the service server 500, after processing the GTP header information and NSI information included in the data packet, the service gateway 300 transmits the data included in the payload to the service server 500. As described above, the payload is transmitted to the service server 500 via a virtual router determined based on the NSI information included in the corresponding data packet.
[0042] As described above, the inventor of the present invention has devised an end-to-end network slicing method of the present invention capable of constructing a network service completely separated from the terminal 100 to the server 500. Hereinafter, the end-to-end network slicing method and the network system for performing the same will be described in more detail.
[0043] FIG. 2 is a diagram schematically showing a connection configuration of the terminal 100, RU, DU, CU, and 5G core 200 according to an embodiment of the present invention.
[0044] FIG. 2(a) shows a configuration in which, in an embodiment of the present invention, the RU and DU / CU are operated in different physical configurations. FIG. 2(b) shows a configuration in which, in another embodiment of the present invention, the RU, DU, and CU are operated as one small cell. FIG. 2(c) shows a configuration in which, in still another embodiment of the present invention, the DU / CU and the 5G core 200 are integrated and operated.
[0045] Specifically, RU (Remote Unit, wireless device), DU (Distributed Unit, distribution device), and CU (Central Unit, central device) are essential components that constitute the RAN (Radio Access Network) in a 5G network. The RU serves as an antenna such as a base station. The DU plays a role in converting the analog signal received through the RU into a digital signal. The CU processes 5G network software services such as cloud and virtualization, functions to reduce communication latency, and has an L2 switch function.
[0046] As shown in FIG. 2(a), the terminal 100 performs wireless communication with the RU, and the RU transmits the analog-form signal received from the terminal 100 to the DU / CU. Here, the DU and CU correspond to one physical device in one embodiment of the present invention, and correspond to a computing system in which one or more physical devices are combined in other embodiments of the present invention. The DU / CU converts the received analog signal into a digital signal, transmits the converted digital signal to the 5G core 200, and the DU / CU transmits the digital signal to the 5G core 200 via the first network. The RIC (RAN Intelligence Controller) connected to the 5G core 200 performs a function of controlling and optimizing the RAN function. As one embodiment of the present invention, the RIC provides multi-vendor interoperability, intelligence, agility, and programmability to the radio access network.
[0047] Figure 2(b) shows an embodiment different from the embodiment in Figure 2(a), in which RU, DU, and CU are operated as small cells. A small cell refers to a base station with low transmission power and narrow coverage, which is a concept contrasted with an existing macro cell having high transmission power and wide coverage. Small cells have the advantages of low construction cost, small size, and high space efficiency compared to macro cells, and are used to complement the communication coverage of existing macro base stations in shadow areas or dense areas, or to construct a 5G specialized network with special requirements such as smart factories or military fields.
[0048] Figure 2(c) shows an embodiment even more different from the embodiments in Figure 2(a) and Figure 2(b), in which RU exists as an independent device, and DU, CU, and 5G core 200 are integrated and operated as one single equipment. Here, DU and CU are independent physical configurations and can be installed in equipment such as the 5G core 200. However, according to an embodiment of the present invention, DU and CU can be virtualized and constructed in the 5G core 200 equipment.
[0049] Furthermore, the configurations shown in each of Figures 2(a) to 2(c) described above are applicable to compatible configurations. For example, the network system of the present invention includes a plurality of RUs. Some of the plurality of RUs communicate with DU / CU in the manner shown in Figure 2(a), and some of the other plurality of RUs communicate with the 5G core 200 in the manner shown in Figure 2(c).
[0050] Figure 3 is a diagram schematically showing the process in which a plurality of terminals 100 according to an embodiment of the present invention communicate with a service gateway 300 via their respective tunnels.
[0051] Specifically, FIG. 3 schematically shows the process in which each of the N terminals 100 communicates with the service gateway (SGW, 300) via N tunnels in the network system of the present invention where the N terminals 100 and the N service servers 500 communicate with each other. For the sake of convenience of understanding, the communication process from the service gateway 300 to the service server 500 is shown in an omitted manner. The communication process from the service gateway 300 to the service server 500 will be described in more detail in the descriptions related to FIGS. 4 to 9.
[0052] As shown in FIG. 3, each of the N terminals 100 communicates with the service gateway 300 via N logically separated tunnels. More specifically, from the terminal 100 to the service gateway 300, according to the configuration in FIG. 2, N logically separated tunnels are formed for each of the N terminals 100, and each of the N tunnels has different tunneling attributes. Here, the tunneling attribute includes tunnel end information for the tunnel end corresponding to the virtual router side end of each tunnel, and the tunnel end information includes the IP address and port number of the input interface of the virtual router directly or indirectly connected to each tunnel. That is, each of the N tunnels has different tunnel end information, and referring only to the configuration shown in FIG. 3, it can be seen that zero-thruster security is realized by network separation from the terminal 100 to the service gateway 300.
[0053] Hereinafter, the end-to-end (from the terminal 100 to the service server 500) network slicing method of the present invention will be described by explaining in which manner the N tunnels connected to the service gateway 300 are connected to the N service servers 500.
[0054] FIG. 4 schematically shows the internal configurations of the service gateway 300 and the controller 400 according to an embodiment of the present invention, and FIG. 5 is a diagram schematically showing VR information transmitted to the service gateway 300 by the controller 400 according to an embodiment of the present invention.
[0055] As shown in FIG. 4, the NSI information transmission step includes a terminal information reception step of receiving terminal information from the terminal 100, and a terminal authentication step of authenticating the corresponding terminal 100 based on the received terminal information. After the authentication of the corresponding terminal 100 is completed, the authentication result information indicating that the corresponding terminal 100 has been authenticated and the NSI information are transmitted to the corresponding terminal 100.
[0056] Further, the data transmission step includes a GTP header information processing step of processing GTP header information with the received data packet by the service gateway 300, and an NSI information processing step of processing NSI information with the data packet in which the GTP header information has been processed by the service gateway 300, and transmitting the data packet in which the GTP header information and the NSI information have been processed to the input port of any one of a plurality of virtual routers determined based on the VR information by the service gateway 300.
[0057] For convenience of explanation, FIG. 4 shows the RU, DU, CU, 5G core 200, first network, and second network omitted. However, referring to FIG. 1, the RU, DU, CU, 5G core 200, first network, and second network of the network system of the present invention are located between the terminal 100 and the service gateway 300.
[0058] Specifically, as described with reference to FIG. 1, the terminal 100 that attempts to communicate with the service server 500 transmits its own terminal information and the NSI request to the controller 400. Here, after receiving the corresponding terminal information, the terminal authentication unit 410 of the controller 400 performs a terminal authentication step of authenticating the corresponding terminal 100 based on the received terminal information. When the authentication of the corresponding terminal 100 is successful, the terminal authentication unit 410 transmits authentication result information regarding the corresponding authentication to the controller 400, and the NSI information transmission unit 420 transmits NSI information including the NSI used by the terminal 100 for communication to the terminal 100.
[0059] NSI (Network Slicing Index) information includes S-NSSAI (Single-Network Slice Selection Assistance Information). The S-NSSAI is a parameter for distinguishing network slicing separately, and consists of SST (Slice / Service type) and SD (Slice Differentiator). The SST represents the service and slice type, and the SD corresponds to a sub-identifier for distinguishing the same SST network. Each SST has a value defined by 3GPP (registered trademark). For example, assuming that there are two slice networks for the eMBB (Enhanced Mobile BroadBand) service, the slice network with an SST value of 1 is composed of two, and an SD value is added to distinguish each of the two slice networks. One of the two slice networks is divided into SST = 1, SD = 1000, and the other is divided into SST = 1, SD = 2000.
[0060] After the terminal 100 is authenticated, the NSI information including the S-NSSAI is included in a data packet together with the data to be transmitted to the service server 500 and is delivered to the service gateway 300. That is, the data packet includes GTP header information generated by the corresponding terminal 100, NSI information received from the controller 400, and a payload including data to be transmitted to the service server 500.
[0061] On the other hand, in FIG. 4, the dotted lines connecting between the terminal authentication unit 410 and the NSI information transmission unit 420 and the terminal 100 do not mean that each of the terminal authentication unit 410 and the NSI information transmission unit 420 is directly connected to the terminal 100, but only mean that the terminal information transmitted from the terminal authentication unit 410 and the NSI information transmitted from the NSI information transmission unit 420 are delivered to the terminal 100. In fact, in the present invention, the terminal authentication unit 410 delivers the terminal information to the service gateway 300, and the NSI information transmission unit 420 delivers the NSI information to the service gateway 300, and then the terminal information and the NSI information are delivered to the terminal 100 via the tunnel between the service gateway 300 and the terminal 100.
[0062] Also, when the terminal 100 is authenticated, the VR information transmission unit 430 of the controller 400 performs a VR information transmission step of transmitting VR information including information about the terminal 100 and VR matching information to the service gateway 300 with reference to FIG. 5, and the transmitted VR information is delivered to the VR information reception unit 310 of the service gateway 300. Thereafter, when the service gateway 300 receives a data packet based on the VR information, it determines a virtual router to which the corresponding data packet is transmitted, and transfers the received data packet to the service server 500 through the determined virtual router. According to an embodiment of the present invention, the service gateway 300 can generate the corresponding virtual router in advance before the data packet is received, and according to another embodiment of the present invention, the corresponding virtual router can be generated when the data packet is received.
[0063] More specifically, when the service gateway 300 receives a data packet, a GTP header information processing step of processing the GTP header information included in the data packet by the GTP header processing unit is performed. Thereafter, an NSI information processing step of processing the NSI information included in the data packet by the NSI information processing unit 330 is performed. The data packet (payload) for which the GTP header information and the NSI information have been processed is transmitted to the service server 500 through the virtual router of the VR unit 340. Hereinafter, the process performed by the service gateway 300 in this way will be described in more detail.
[0064] FIG. 6 is a diagram schematically showing an execution process of a GTP header information processing step according to an embodiment of the present invention.
[0065] As shown in FIG. 6, the service gateway 300 includes a first port corresponding to a physical interface, and the GTP header information processing step transmits a first intermediate data packet obtained by removing GTP header information from a data packet transmitted through the first port to the NSI information processing unit 330 of the service gateway 300, and transmits the first intermediate data packet through a GPR tunnel corresponding to the removed GTP header information.
[0066] Specifically, as shown in FIG. 6, a plurality of tunnels are connected to a first port which is a physical interface included in the service gateway 300, and a data packet received by the first port is transmitted to the GTP header information processing unit 320. On the other hand, although only one first port is shown in FIG. 6, this only corresponds to one embodiment of the present invention, and according to other embodiments of the present invention, the service gateway 300 can include a plurality of first ports.
[0067] As described with reference to FIG. 3, each of the N tunnels connecting the terminal 100 and the service gateway 300 has different tunneling attributes, the tunneling attributes include tunnel end information, and the tunnel end information includes the IP address or port number of the first port connected to the corresponding tunnel. The tunnel end information can be determined by the DU / CU or the 5G core 200 as one embodiment of the present invention.
[0068] The N data packets received at the N first ports (three in FIGS. 6 to 9) are transmitted to the GTP header information processing unit 320, and the GTP header information processing unit 320 performs a GTP header information processing step of removing the GTP header information included in each of the received N data packets. Here, the data packet from which the GTP header information has been removed is referred to as a first intermediate data packet. That is, the GTP header information processing unit 320 generates N first intermediate data packets by the GTP header information processing step, and transmits the generated N first intermediate data packets to the NSI information processing unit 330. Here, each of the N first intermediate data packets is transmitted to the NSI information processing unit 330 via a GPRS tunnel corresponding to its removed GTP header information.
[0069] GTP (GPRS Tunneling Protocol) is a group of IP-based communication protocols used to transmit GPRS (General Packet Radio Service) within GSM, UMTS, and LTE networks. In the 3GPP architecture, GTP and Proxy Mobile IPv6 base interfaces are used at various interface points. That is, the GTP header information includes tunnel end information regarding the tunnel from the corresponding terminal 100 to the first port.
[0070] FIG. 7 schematically shows the execution process of the NSI information processing step according to an embodiment of the present invention, FIG. 8 schematically shows the VR matching information included in the VR information according to an embodiment of the present invention, and FIG. 9 is a diagram schematically showing the process in which the second intermediate packet data according to another embodiment of the present invention is transmitted to the service server 500.
[0071] As shown in FIGS. 7 to 9, the service gateway 300 includes a second port and a third port corresponding to virtual interfaces. The second port corresponds to the input port of the virtual router, and the third port corresponds to the output port of the virtual router. After receiving a first intermediate data packet from which GTP header information has been removed from the data packet, the NSI information processing step removes NSI information from the first intermediate data packet and transmits a second intermediate data packet to the VR unit 340 of the service gateway 300. The second intermediate data packet is transmitted to the second port of the virtual router corresponding to the removed NSI information. The second port to which the second intermediate data packet is transmitted is determined based on VR matching information including information regarding the second port determined by the NSI information.
[0072] Specifically, when the NSI information processing unit 330 receives a first intermediate data packet from the GTP header information processing unit 320, it performs an NSI information processing step of removing NSI information from the received first intermediate data packet. Here, the data packet obtained by removing NSI information from the first intermediate data packet is referred to as a second intermediate data packet. Thereafter, the NSI information processing unit 330 transfers the second data packet to the VR unit 340. More specifically, the second intermediate data packet is transmitted to any one of the plurality of virtual routers included in the VR unit 340. The virtual router through which the second intermediate data packet is transmitted is determined based on the NSI information removed in the NSI information processing step and the VR matching information included in the VR information with reference to FIG. 5. That is, since the NSI information included in each of the N first intermediate data packets is different from each other, each of the N second intermediate data packets is transmitted to the service server 500 through a different virtual router.
[0073] For example, as an embodiment of the present invention, the VR matching information corresponds to information in a table form as shown in FIG. 8. According to another embodiment of the present invention, the virtual router is matched by the NSI in the form of a pre-set or pre-saved rule. According to still another embodiment of the present invention, based on rules that dynamically change according to a network or communication environment or a specific period, a virtual router to be matched is determined for each NSI.
[0074] As shown in FIG. 8, in the case of VR matching information in a table form, if the NSI included in the first intermediate data packet received by the NSI information processing unit 330 corresponds to NSI#1, the NSI information processing unit 330 removes the NSI information of the corresponding first intermediate data packet and transmits the second intermediate data packet to virtual router #2 (VR#2). If the NSI included in the received first intermediate data packet corresponds to NSI#2, the NSI information processing unit 330 removes the NSI information of the corresponding first intermediate data packet and transmits the second intermediate data packet to virtual router #m (VR#m, where m is a natural number of 1 or more).
[0075] On the other hand, as shown in FIG. 9, a second port and a third port are located at each of the input and output ends of a plurality of VRs included in the VR unit 340. The second port and the third port correspond to a virtual interface. The second intermediate data packet transmitted from the NSI information processing unit 330 is transmitted to the virtual router via the second port, and the second intermediate data packet transmitted to the virtual router is transmitted to the service server 500 via the third port. That is, it is desirable that the VR matching information includes port information of the second port based on the NSI information included in the data packet.
[0076] For each of the plurality of virtual routers included in the VR unit 340, there are a second port and a third port. When the virtual routers are different, the port information including the IP information and port number of the second port of each virtual router is also different. Therefore, data packets transmitted from other terminals 100 are logically separated even at the service gateway 300 and transmitted to the service server 500. The plurality of third ports are connected to one or more physical interfaces included in the service gateway 300, and the second intermediate data packets are transmitted to the service server 500 via the third ports and the physical interfaces.
[0077] FIG. 10 is a diagram schematically showing a process in which each of a plurality of terminals 100 and a plurality of service servers 500 according to an embodiment of the present invention communicate via a logically separated communication network.
[0078] As shown in FIG. 10, data packets transmitted from each of the N terminals 100 are transmitted to the service gateway 300 via N tunnels, and the data packets received by the service gateway 300 are transmitted to the N service servers 500 via N virtual routers. That is, according to the network system including the 5G specialization network of the present invention and the end-to-end network slicing method performed in the corresponding system, an effect of implementing zero-trust security can be obtained for each terminal 100 from the terminal 100 to the service server 500.
[0079] FIG. 11 is a diagram exemplarily showing an internal configuration of a computing device 11000 according to an embodiment of the present invention.
[0080] The service server 500 mentioned in the description of FIG. 1 can include some or all of the components of the computing device 11000 in FIG. 11 described later. According to other embodiments of the present invention, any one or more of the terminal or the 5G core can include some or all of the components of the computing device 11000 in FIG. 11 described later.
[0081] As shown in FIG. 11, the computing device 11000 includes at least one processor 11100, a memory 11200, a peripheral device interface 11300, an input / output subsystem 11400, a power circuit 11500, and a communication circuit 11600.
[0082] Specifically, the memory 11200 includes, for example, high-speed random access memory, magnetic disks, SRAM, DRAM, ROM, flash memory, or non-volatile memory. The memory 11200 includes software modules, command sets, or various other data necessary for the operation of the computing device 11000.
[0083] Here, accessing the memory 11200 from other components such as the processor 11100 and the peripheral device interface 11300 is controlled by the processor 11100. The processor 11100 may be single or multiple, and may include processors in the form of GPUs and TPUs to improve the arithmetic processing speed.
[0084] The peripheral device interface 11300 couples the input and / or output peripheral devices of the computing device 11000 to the processor 11100 and the memory 11200. The processor 11100 executes software modules or command sets stored in the memory 11200 to perform various functions for the computing device 11000 and process data.
[0085] The input / output subsystem 11400 couples various input / output peripheral devices to the peripheral device interface 11300. For example, the input / output subsystem 11400 includes a controller for coupling a peripheral device such as a monitor, keyboard, mouse, printer, or, if necessary, a touch screen or sensor to the peripheral device interface 11300. According to another aspect, the input / output peripheral device can also be coupled to the peripheral device interface 11300 without passing through the input / output subsystem 11400.
[0086] The electrical power circuit 11500 can supply power to all or part of the components of the terminal device. For example, the power circuit 11500 includes a power management system, one or more power sources such as a battery or alternating current (AC), a charging system, a power failure detection circuit, a power converter or inverter, a power status indicator, or any other component for power generation, management, and distribution.
[0087] The communication circuit 11600 enables communication with other computing devices using at least one external port. Or, as described above, if necessary, the communication circuit 11600 can include an RF circuit and enable communication with other computing devices by transmitting and receiving RF signals, also known as electromagnetic signals.
[0088] Such an embodiment of FIG. 11 is merely an example of the computing device 11000, and the computing device 11000 may have a configuration or arrangement in which some components in FIG. 11 are omitted, further components in FIG. 11 are provided, or two or more components are combined. For example, a computing device for a communication terminal in a mobile environment may further include a touch screen, a sensor, etc. in addition to the components as shown in FIG. 11, and the communication circuit 1160 may also include circuits for RF communication of various communication methods (WiFi, 3G, LTE, Bluetooth, NFC, Zigbee, etc.). The components included in the computing device 11000 are implemented in the form of hardware, software, or a combination of both hardware and software, including one or more signal processing or integrated circuits specialized for applications.
[0089] The method according to an embodiment of the present invention is embodied in the form of program instructions to be executed by various computing devices and recorded on a computer-readable medium. In particular, the program according to this embodiment is composed of a PC-based program or an application dedicated to a mobile terminal. The application to which the present invention is applied is installed on a user terminal through a file provided by a file distribution system. As an example, the file distribution system includes a file transmission unit (not shown) that transmits the file in response to a request from a user terminal device.
[0090] The apparatuses described above are implemented by hardware components, software components, and / or combinations of hardware components and software components. For example, the apparatuses and components described in the embodiments can be implemented using one or more general-purpose computers or special-purpose computers, such as, for example, a processor, a controller, an ALU (arithmetic logic unit), a digital signal processor, a microcomputer, an FPGA (field programmable gate array), a PLU (programmable logic unit), a microprocessor, or any other device that executes and responds to instructions. The processing device can execute an operating system (OS) and one or more software applications executed on the operating system. Further, the processing device can also access, store, manipulate, process, and generate data in response to the execution of the software. For ease of understanding, the processing device may be described as being used singly, but those having ordinary knowledge in the relevant technical field will understand that the processing device may also include a plurality of processing elements and / or a plurality of types of processing elements. For example, the processing device includes a plurality of processors or one processor and one controller. Also, other processing configurations, such as a parallel processor, are possible.
[0091] Software includes a computer program, code, instructions, or one or more combinations thereof, and can configure a processing device or instruct the processing device, either independently or collectively, to operate as desired. Software and / or data can be embodied permanently or temporarily in any type of machine, component, physical device, virtual equipment, computer storage medium or device, or signal wave being transmitted, and be analyzed by the processing device or provide instructions or data to the processing device. Software can also be distributed over computing devices connected by a network and stored or executed in a distributed manner. Software and data are stored in one or more computer-readable recording media.
[0092] The method according to the embodiment is embodied in the form of program instructions performed by various computer means and recorded on a computer-readable medium. The computer-readable medium can include program instructions, data files, data structures, etc. alone or in combination. The program instructions recorded on the medium are either specially designed and configured for the embodiment or are known to and usable by those skilled in the art of computer software. Computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical media such as CD-ROMs, DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program instructions such as ROMs, RAMs, flash memories, etc. Program instructions include not only machine language code generated by a compiler but also high-level language code executable by a computer using an interpreter or the like. The hardware device is configured to operate as one or more software modules to perform the operations of the embodiment, and vice versa.
[0093] According to the present invention, even in a network system that uses two types of networks with different network operating countries or operators, end-to-end zero-trust security can be implemented from the terminal to the server.
[0094] Also, according to the present invention, by configuring independent networks for terminals, services, and servers, network access can be controlled and regulated, thereby enhancing security.
[0095] Furthermore, according to the present invention, by forming logically separated networks, security can be enhanced and costs can be reduced compared to constructing physically independent networks.
[0096] Also, according to the present invention, since each of a plurality of terminals is operated in an independent network, even if one terminal is hacked, damage to the remaining terminals can be minimized.
[0097] As described above, although the embodiments have been described with reference to limited embodiments and drawings, those of ordinary skill in the relevant technical field can make various modifications and variations from the above description. For example, the described technology may be performed in an order different from the described method, and / or the components of the described system, structure, device, circuit, etc. may be combined or assembled in a form different from the described method, or may be opposed or replaced by other components or equivalents, and appropriate results can still be achieved.
[0098] Therefore, other implementations, other embodiments, and equivalents to the claims also fall within the scope of the claims described below.
Claims
1. An end-to-end network slicing method performed in a network system including a 5G specialized network, The network system includes a 5G core, a service gateway, and a controller; an NSI information transmission step of authenticating the terminal by the controller and transmitting NSI information including the NSI requested by the terminal to the corresponding terminal; a VR information sending step of sending, by the controller, VR information including terminal information for the authenticated terminal and VR matching information related to a virtual router determined by the NSI to the service gateway; a data receiving step of receiving, by a serving gateway, a data packet from the authenticated terminal, the data packet including a GTP header information, an NSI information, and a payload; a data transmission step of transmitting, by a service gateway, the data packet in which the GTP header information and the NSI information have been processed to a service server through a virtual router determined based on the VR information; The terminal and the 5G core communicate with each other via a first network located between the terminal and the 5G core; The 5G core and the service gateway communicate via a second network located between the 5G core and the service gateway; A network slicing method, characterized in that the first network and the second network correspond to different networks from each other.
2. The network slicing method of claim 1, wherein the service gateway generates a plurality of virtual routers to enable communication between a plurality of terminals and a plurality of service servers, and the virtual routers used for communication between different terminals and different service servers are different, so that communications between the plurality of terminals and the plurality of service servers are logically separated from each other.
3. The NSI information transmitting step includes: a terminal information receiving step of receiving terminal information from a terminal; A terminal authentication step of authenticating the terminal based on the received terminal information; The network slicing method according to claim 1, further comprising: transmitting authentication result information indicating that the corresponding terminal has been authenticated and the NSI information to the corresponding terminal after authentication of the corresponding terminal is completed.
4. The data transmitting step includes: a GTP header information processing step of processing GTP header information in the received data packet by the serving gateway; The network slicing method according to claim 1, further comprising an NSI information processing step of processing NSI information in the data packet in which the GTP header information has been processed by a service gateway, and transmitting the data packet in which the GTP header information and the NSI information have been processed to an input port of a virtual router determined by one of a plurality of virtual routers based on the VR information.
5. the service gateway includes a first port corresponding to a physical interface; The GTP header information processing step includes: The network slicing method of claim 4, further comprising: transmitting a first intermediate data packet in which GTP header information has been removed from the data packet transmitted through the first port to an NSI information processing unit of the service gateway; and transmitting the first intermediate data packet through a GPRS tunnel corresponding to the removed GTP header information.
6. the service gateway includes a second port and a third port corresponding to a virtual interface, the second port corresponds to an input port of the virtual router, and the third port corresponds to an output port of the virtual router; The NSI information processing step includes: After receiving a first intermediate data packet in which GTP header information has been removed from the data packet, send a second intermediate data packet in which NSI information has been removed from the first intermediate data packet to a VR unit of the service gateway, and the second intermediate data packet is sent to a second port of a virtual router corresponding to the removed NSI information; The network slicing method of claim 4, wherein the second port to which the second intermediate data packet is transmitted is determined based on VR matching information including information for the second port determined by the NSI information.
7. A network system including a 5G specialized network performing an end-to-end network slicing method, The network system includes a 5G core, a service gateway, and a controller; an NSI information transmission step of authenticating the terminal by the controller and transmitting NSI information including the NSI requested by the terminal to the corresponding terminal; a VR information sending step of sending, by the controller, VR information including terminal information for the authenticated terminal and VR matching information related to a virtual router determined by the NSI to the service gateway; a data receiving step of receiving, by a serving gateway, a data packet from the authenticated terminal, the data packet including a GTP header information, an NSI information, and a payload; A data transmission step of transmitting the data packet, in which the GTP header information and the NSI information have been processed, to a service server by a service gateway through a virtual router determined based on the VR information; The terminal and the 5G core communicate with each other via a first network located between the terminal and the 5G core; The 5G core and the service gateway communicate via a second network located between the 5G core and the service gateway; A network system, wherein the first network and the second network correspond to networks different from each other.
Citation Information
Patent Citations
User data processing device, network interface, and method
JP2021170729A
Two-way communication system using gate server
KR102512037B1
Method and system for service switching using service tags
US20140334485A1
System and Methods for Path-Aware and Path-Assured Secure Virtual Private Lines and Secure Network Slices using Enhanced Digital Certificates in Multi-Vendor Multi-Domain Networks
US20220141192A1