Virtual private network control device, wireless communication system, virtual private network control method, and program
The virtual private network controller addresses inefficiencies in resource utilization by dynamically allocating hardware resources based on user needs, enhancing network performance and functionality through optimized configurations.
Patent Information
- Application Number
- JP2024528126
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-06-20
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2042-06-20
AI Technical Summary
Conventional wireless communication networks face decreased utilization efficiency of hardware resources due to increasing variations in network slices, leading to inefficient resource occupation as performance and sophistication improve.
A virtual private network controller dynamically allocates hardware resources on demand based on user communications, determining optimal configurations and resource allocations for each user's specific needs, utilizing a determination unit and control instruction unit to manage network virtualization and resource distribution.
This approach enhances the utilization efficiency of hardware resources by optimizing resource allocation and configuration in response to user demands, improving network performance and functionality.
Smart Images

Figure 0007810261000001 
Figure 0007810261000002 
Figure 0007810261000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a virtual private network controller, wireless The present invention relates to a communication system, a virtual private network control method, and a program. [Background technology]
[0002] Regarding wireless communication resource allocation control technology, research is being conducted on network and session control technology that allocates hardware resources on demand according to the occurrence of user communications. For example, 5G wireless networks use virtual network (network slice) technology according to service requirements.
[0003] A network slice is composed of multiple physical resources that are interconnected and divided into virtualized functions and virtual networks in the three sections of the radio access, transport, and core network. Management and control of the network slice is performed on the M-plane. Control of communications for each user terminal is performed on the C-plane. Additionally, quality control, billing, and routing to the target server for each service on the communication path between the terminal and the service are performed on the U-plane.
[0004] Meanwhile, there is an emerging need for higher performance or more advanced communication quality and functionality, such as achieving large capacity, low latency and low jitter, and powerful encryption processing. This requires that the hardware resources required to achieve high performance in software, server processing, etc., be flexibly configured and allocated according to the performance or functionality required for the services used by users. In conventional architectures, hardware resources are virtualized and combined in advance from the M-plane, and then the C-plane virtualizes functions in response to requests from terminals to determine the priority of processing to ensure the required quality, and performs calculation processing, etc. (Non-Patent Documents 1 to 5, etc.). [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] 3GPP TS28.531, "Management and orchestration; Provisioning;" [Non-patent document 2] GSMA NG116, Generic Network Slice Template Version 2.0, Oct. 2019 [Non-patent document 3] 3GPP TS28.541, "5G Network Resource Model (NRM)" [Non-patent document 4] ETSI GR NFV-IFA 029, Report on the Enhancements of the NFV architecture towards "Cloud-native" and "PaaS" [Non-patent document 5] 3GPP TS23.501, "System architecture for the 5G System (5GS)" Summary of the Invention [Problem to be solved by the invention]
[0006] With conventional technology, as performance and sophistication improve and the variations in network slices increase, the number of variations occupies the network hardware resources, resulting in a decrease in the utilization efficiency of most resources.
[0007] The disclosed technology aims to improve the utilization efficiency of hardware resources in a communication network. [Means for solving the problem]
[0008] The disclosed technology is a method for controlling communication between data relating to users of a communication service, information indicating attributes of a virtualized network for each user, and a terminal of the user. of a determination unit that determines a configuration of the network virtualized for each user in response to a request from the terminal based on the information indicating the network configuration and information indicating the configuration of a physical network; and a control instruction unit that instructs a device that controls the transport device or the server device to transfer data or logic for processing to a transport device that performs data transfer or a server device that performs processing, based on the determined configuration of the network virtualized for each user. The determination unit determines a base at which the virtualized network for each user is to be deployed and a required resource allocation amount as profile requirements that the virtualized network for each user must satisfy, and determines a configuration of the virtualized network for each user depending on whether there are resources of the transport device or the server device that satisfy the profile requirements. It is a virtual private network controller. [Effects of the Invention]
[0009] This makes it possible to improve the utilization efficiency of hardware resources in a communication network. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram illustrating a configuration of a conventional wireless communication network. [Figure 2] FIG. 1 is a diagram illustrating a processing flow in a conventional wireless communication network. [Figure 3] 1 is a diagram showing a configuration of a wireless communication network according to an embodiment of the present invention; [Figure 4] 1 is a diagram illustrating an example of a functional configuration of a virtual private network control device according to an embodiment of the present invention; [Figure 5] FIG. 4 is a diagram showing an example of information stored in a user database according to an embodiment of the present invention. [Figure 6] 3 is a diagram showing an example of information stored in a virtual private network configuration profile management device according to an embodiment of the present invention; FIG. [Figure 7] 3 is a diagram showing an example of information stored in a network configuration information management device according to an embodiment of the present invention; FIG. [Figure 8]FIG. 2 is a diagram illustrating an example of a configuration of a transport device resource pool according to an embodiment of the present invention. [Figure 9] FIG. 2 is a diagram illustrating an example of a configuration of a server device group according to an embodiment of the present invention. [Figure 10] 1 is a flowchart illustrating an example of a processing flow according to an embodiment of the present invention. [Figure 11] FIG. 1 is a diagram for explaining an example in which an embodiment of the present invention is applied to a 5G network. [Figure 12] FIG. 2 illustrates an example of a hardware configuration of a computer. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, an embodiment of the present invention (the present embodiment) will be described with reference to the drawings. The embodiment described below is merely an example, and the embodiment to which the present invention is applied is not limited to the following embodiment.
[0012] <Prior Art> First, the prior art will be described.
[0013] Figure 1 is a diagram illustrating the configuration of a conventional wireless communication network. A network slice in a 5G wireless network is divided into three sections, the radio access, transport, and core networks, and consists of multiple physical resources that are interconnected and divided into virtualized functions and virtual networks.
[0014] The management and control of network slices is performed on the M-plane. The control of communications for each user terminal is performed on the C-plane. The U-plane also performs quality control, billing, and routing to the target server for each service on the communication path between the terminal and the service.
[0015] For example, Non-Patent Document 1 discloses M-plane functions such as NSMS (Network Slice Management Service) / NSSMS (Network Slice Subnet Management Service) as provisions for the management and control of network slices by network operators.
[0016] Furthermore, Non-Patent Documents 2 and 3 disclose information on instances called NSI (Network Slice Instance) / NSSI (Network Slice Subnet Instance) and slice profiles, which are used as units for managing or controlling network slices.
[0017] Furthermore, Non-Patent Document 4 discloses that virtual network functions (VNFs) and virtual networks, which are configured by controlling and configuring hardware resources such as network virtualization platforms and transport platforms from orchestrators, controllers, etc., are managed by linking them to instances as network slices.
[0018] Figure 2 is a diagram for explaining the processing flow in a conventional wireless communication network. C-plane functions include the connection and allocation of terminals to network slices, authentication at the start and end of communication on the network slice, and control of communication paths called QoS flows, performed by the Centralized Unit (CU), Access and Mobility Management Function (AMF), Network Slice Selection Function (NSSF), and Session Management Function (SMF) in the 5G core network.
[0019] Specifically, in conjunction with the registration request processing from the terminal in the AMF, the NSSF accommodates the terminal in the appropriate network slice based on the service conditions in the user profile. Next, for communication with each service, the SMF located in each network slice manages sessions for each terminal and service, and exchanges quality control and connection path control information for each QoS flow for each terminal.
[0020] Furthermore, as a U-plane function, a Centralized Unit - User Plane (CU-UP), a User plane function (UPF), etc. execute quality control such as bandwidth guarantee required for each service.
[0021] <Conventional problems> There is an emerging need for higher performance and more advanced communication quality and functionality, such as low latency and low jitter, powerful encryption processing, etc. This requires that the hardware resources required to achieve high performance in software and server processing be flexibly configured and allocated according to the performance or functionality required for the services used by users.
[0022] In conventional architectures, hardware resources are virtualized and combined in advance from the M-plane, and then the necessary quality assurance, calculation processing, etc. are performed in the virtualized functions in the C-plane in response to requests from the terminal.
[0023] With conventional technology, as performance and sophistication improve and the variations in network slices increase, the number of variations occupies the network hardware resources, resulting in a decrease in the utilization efficiency of most resources.
[0024] <Outline of this embodiment> In this embodiment, in order to solve the above-mentioned conventional problems, a network and session control is realized that allocates hardware resources on demand in response to user communications, thereby improving the utilization efficiency of hardware resources in a wireless communication network.
[0025] <Overall Configuration of the Present Embodiment> 3 is a diagram showing the configuration of a wireless communication network according to an embodiment of the present invention. The wireless communication network 1 includes a virtual private network control device 10, a user database 20, a virtual private network configuration profile management device 30, an authentication and session control device 40, a network configuration information management device 50, a transport device resource pool 60, and a server device group 70.
[0026] The virtual private network control device 10 is communicably connected to a user database 20, a virtual private network configuration profile management device 30, an authentication and session control device 40, a network configuration information management device 50, a transport device resource pool 60, and a server device group 70. Each communication method may be wireless or wired.
[0027] The virtual private network control device 10 performs design control of specific communication functions in conjunction with C-plane control (session control) such as terminal authentication, session control, and mobility control. The virtual private network control device 10 also performs design control of network functions that combine user subscription service attribute information, slice identification information, session information, access line / area information, location information, etc. with network slice function configuration conditions, network configuration information, etc.
[0028] The virtual private network control device 10 also determines the amount of hardware and resources for general-purpose devices such as server devices, accelerator devices, programmer switches, and white box switches that deploy data transfer and processing logic based on the network design. Furthermore, the virtual private network control device 10 realizes a function for redesigning the configuration of communication lines based on access lines / areas, location information, etc. after a terminal moves in conjunction with session information, and the movement or redeployment of data transfer processing logic.
[0029] The user database 20 stores data relating to users of communication services, such as communication service user IDs, contracted service types, virtual private network identification information for providing the service, communication session information, access lines, area information, and location information.
[0030] The virtual private network configuration profile management device 30 stores identification information of the virtual network to be accommodated for each communication service, information on network functions to be deployed within the virtual private network, communication quality conditions, applicable access lines, applicable area information, autonomous operation policy information of the virtual private network, etc.
[0031] The authentication and session control device 40 controls the authentication of a communication service with a terminal on a network and the communication session at the start of service use.
[0032] The network configuration information management device 50 manages physical configuration information of server devices and transport devices, information on the physical resources within each device (CPU (Central Processing Unit) / memory / storage / FPGA (field-programmable gate array) / GPU (Graphics Processing Unit) / NIC (Network Interface Card) / SmartNIC, etc.), information on the physical wiring connection configuration between each physical device, and the usage status of resources possessed by physical devices of logical network functions.
[0033] The transport device resource pool 60 is a group of devices that perform data transfer. Each transport device included in the transport device resource pool 60 is a device to which software functions can be written.
[0034] The transport device resource pool 60 comprises a transport device control management device 61, a data transfer and processing logic repository 62, a programmable switch 63, and a white-box device 64. The transport device control management device 61 manages the resources of the transport device resource pool and controls and manages the allocation and status of data transfer and processing logic to transport devices. The data transfer and processing logic repository 62 manages the software groups deployed in the programmable areas on the server devices and transport devices.
[0035] The server device group 70 is a group of devices that perform processing, such as a general-purpose server 73 and an accelerator 74. Each server device included in the server device group 70 is a device to which software functions can be written. The server device group 70 includes a server device control management device 71, a data transfer / processing logic repository 72, the general-purpose server 73, and the accelerator 74.
[0036] The server device control management device 71 manages the server resources of the server device group 70, and controls and manages the status of data transfer and allocation of processing logic to the server devices.
[0037] <Functional configuration of the virtual private network control device according to this embodiment> 4 is a diagram showing an example of the functional configuration of a virtual private network control device according to an embodiment of the present invention. The virtual private network control device 10 includes a user data processing unit 11, a virtual private network profile processing unit 12, a communication control information processing unit 13, a physical network configuration processing unit 14, a specific communication virtual private network design and configuration determination unit 15, a specific communication virtual private network deployment site and resource amount determination unit 16, a communication quality and network status determination unit 17, a specific communication virtual private network control instruction unit 18, and a specific communication virtual private network management and monitoring unit 19.
[0038] The user data processing unit 11 processes the user data stored in the user database 20. Specifically, the user data processing unit 11 acquires from the user database 20 a user profile included in the user data.
[0039] The virtual-only network profile processing unit 12 acquires information indicating the attributes of the accommodating network stored in the virtual-only network configuration profile management device 30. Specifically, the virtual-only network profile processing unit 12 acquires the virtual-only network configuration profile from the virtual-only network type identification information.
[0040] The communication control information processing unit 13 acquires communication control information. The communication control information is information for controlling communication between terminals. Specifically, the communication control information processing unit 13 acquires session information from the authentication and session control device 40. The session information is an example of communication control information.
[0041] The physical network configuration processing unit 14 acquires data (information) that configures the physical network. Specifically, the physical network configuration processing unit 14 acquires physical configuration information from the network configuration information management device 50. The physical configuration information is data (information) that indicates the configuration of the physical network.
[0042] The specific communication virtual private network design and configuration determination unit 15 determines the design and configuration of a virtual private network for the specific communication for the user. Specifically, the specific communication virtual private network design and configuration determination unit 15 designs the configuration of physical device resources corresponding to the virtual private network configuration profile.
[0043] The specific communication virtual private network deployment site / resource amount determination unit 16 determines the site where the virtual private network is deployed and the amount of resources required to be allocated. The configuration of physical device resources and the amount of resources required to be allocated are examples of requirements that the virtual private network configuration profile must satisfy (virtual private network configuration profile requirements).
[0044] The communication quality and network state determination unit 17 determines whether or not there is a physical device resource that satisfies the virtual private network configuration profile requirements based on the communication quality and network state of the virtual private network for each physical device resource.
[0045] The specific communication virtual private network design and configuration determination unit 15, the specific communication virtual private network deployment site and resource amount determination unit 16, and the communication quality and network status determination unit 17 work together to function as a determination unit that determines the configuration of a virtualized network for each user in response to a request from a terminal.
[0046] The specific communication virtual private network control instruction unit 18 instructs the virtual private network control. Specifically, the specific communication virtual private network control instruction unit 18 instructs the transfer of data transfer processing logic to the transport device control management device or server device control management device of the target base based on the design results.
[0047] The specific communication virtual private network management and monitoring unit 19 monitors the specific communication virtual private network to acquire physical device resource utilization information. The physical device resource utilization information is information indicating the utilization status of the physical network.
[0048] <Information related to this embodiment> Next, information according to this embodiment will be described.
[0049] FIG. 5 is a diagram showing an example of information stored in the user database according to the embodiment of the present invention.
[0050] The user database 20 stores information necessary for identifying the type of virtual private network required to provide communication services for each communication service user, the applicable access, the area such as region, location specification, and the identification of the communication session to be accommodated in the virtual private network.
[0051] Specifically, the user database 20 stores user ID / terminal identification information 21, authentication information 22, access line identifier 23, location area identifier 24, location information 25, subscribed service information 26, virtual private network identification information 27, communication session information 28, and accommodating virtual private network control device identification information 29.
[0052] The user ID / terminal identification information 21 is information for uniquely identifying a user as a user ID and for identifying the terminal being used. The authentication information 22 is information for authenticating a user communicating on the network. The access line identifier 23 is information for identifying the line from which the access is made.
[0053] The serving area identifier 24 is information for identifying the serving area that specifies the region accessed by the terminal. The location information 25 is information for specifying the location of the terminal. The subscribed service information 26 is information indicating the services to which the user subscribes. The subscribed service information 26 enables the virtual private network control device 10 to identify the services with which the terminal will communicate.
[0054] The virtual private network identification information 27 is information for identifying the virtual private network that provides a communication path to the subscribed service. The communication session information 28 is information for identifying and managing communications from the terminal. The accommodation virtual private network control device identification information 29 is information for identifying the accommodation virtual private network control device 10.
[0055] 6 is a diagram showing an example of information stored in a virtual private network configuration profile management device according to an embodiment of the present invention. The virtual private network configuration profile management device 30 stores, as basic attribute values when configuring a virtual private network, logical topology, data transfer processing logic configuration and order information, applicable area / access line type information, quality conditions for the virtual private network, information indicating the type of hardware resource to be applied, resource design templates, etc.
[0056] Specifically, the virtual private network configuration profile management device 30 stores virtual private network type identification information 31, logical topology information 32, data transfer / processing logic configuration / order information 33, applicable area / access line type information 34, virtual private network quality conditions 35, applicable hardware resource type information 36, and resource design template 37.
[0057] The virtual private network type identification information 31 is information for identifying the type of virtual private network to be designed and controlled. The logical topology information 32 is information indicating the logical network configuration. The data transfer / processing logic configuration / order information 33 is information indicating the configuration and application order of the data transfer / processing logic group included in the virtual private network.
[0058] The applicable area / access line type information 34 is information used to determine the area / access line that can be connected to the virtual private network by location, area, and line. The virtual private network quality conditions 35 are information indicating the conditions for communication quality related to the service on the virtual private network.
[0059] The applicable hardware resource type information 36 is information indicating the type of hardware resource that can be applied in the configuration of a virtual private network. The resource design template 37 is a template indicating a typical resource deployment pattern, design, etc.
[0060] 7 is a diagram showing an example of information stored in a network configuration information management device according to an embodiment of the present invention. The network configuration information management device 50 stores information indicating the physical topology, device placement, device types, physical resources, etc. of the transport device resource pool 60 and the server device group 70.
[0061] Specifically, the network configuration information management device 50 stores a transport physical topology 51, a server device physical topology 52, transport device layout information 53, server device layout information 54, transport device type information 55, server device type information 56, transport device physical resource information 57, and server device physical resource information 58.
[0062] The transport physical topology 51 is information indicating the physical connection configuration between the transport device and the deployment base. The server device physical topology 52 is information indicating the physical connection configuration between the server device and the deployment base.
[0063] The transport device location information 53 is information indicating the location of each transport device included in the transport device resource pool 60. The server device location information 54 is information indicating the location of each server device included in the server device group 70.
[0064] The transport device type information 55 is information indicating the type of each transport device included in the transport device resource pool 60. The server device type information 56 is information indicating the type of each server device included in the server device group .
[0065] The transport device physical resource information 57 is information indicating the type of resources included in each transport device included in the transport device resource pool 60. The server device physical resource information 58 is information indicating the type of resources included in each server device included in the server device group 70.
[0066] <Virtual Private Network Device According to the Present Embodiment> Next, a virtual private network device according to this embodiment will be described.
[0067] 8 is a diagram showing an example of the configuration of a transport device resource pool according to an embodiment of the present invention. The transport device resource pool 60 includes a transport device control management device 61, a data transfer and processing logic repository 62, a programmable switch 63, and a white-box device 64.
[0068] The transport device control management device 61 includes a transport device control API function unit 611 , a transport device status management unit 612 , a transport device control management IF unit 613 , and a data transfer and processing logic control unit 614 .
[0069] The transport device control API function unit 611 provides an API (Application Programming Interface) for controlling the transport device. The transport device status management unit 612 manages the status of the transport device. The transport device control management IF unit 613 provides an interface for controlling the transport device.
[0070] The data transfer / processing logic control unit 614 controls the data transfer / processing logic transferred to the transport device. Specifically, the data transfer / processing logic control unit 614 transfers the data transfer / processing logic to the transport device including the programmable switch 63, the white box device 64, etc., and after the transferred data transfer / processing logic is activated, sets the control information required for each session to set the content to be applied to each communication.
[0071] The data transfer / processing logic repository 62 stores data transfer / processing logic identification information 621 and data transfer / processing logic information 622 .
[0072] The data transfer / processing logic identification information 621 is an identifier for identifying the data transfer / processing logic. The data transfer / processing logic information 622 is information indicating the data transfer / processing logic to be transferred to each transport device.
[0073] The programmable switch 63 and the white box device 64 are examples of transport devices, and other types of devices may be used.
[0074] 9 is a diagram showing an example of the configuration of a server device group according to an embodiment of the present invention. The server device group 70 includes a server device control management device 71, a data transfer / processing logic repository 72, a general-purpose server 73, and an accelerator 74.
[0075] The server device control management device 71 includes a server device control API function unit 711 , a server device status management unit 712 , a server device control management IF unit 713 , and a data transfer and processing logic control unit 714 .
[0076] The server device control API function unit 711 provides an API (Application Programming Interface) for controlling the server device. The server device status management unit 712 manages the status of the server device. The server device control management IF unit 713 provides an interface for controlling the server device.
[0077] The data transfer / processing logic control unit 714 controls the data transfer / processing logic transferred to the server device. Specifically, the data transfer / processing logic control unit 714 transfers the data transfer / processing logic to the server device, including the general-purpose server 73, accelerator 74, etc., and sets control information required for each session to set the content to be applied to each communication after the transferred data transfer / processing logic is started.
[0078] The data transfer / processing logic repository 72 stores data transfer / processing logic identification information 721 and data transfer / processing logic information 722 .
[0079] The data transfer / processing logic identification information 721 is an identifier for identifying the data transfer / processing logic. The data transfer / processing logic information 722 is information indicating the data transfer / processing logic to be transferred to each server device.
[0080] The general-purpose server 73 and the accelerator 74 are examples of server devices, and may be other devices.
[0081] <Operation According to the Present Embodiment> 10 is a flowchart showing an example of a process flow according to an embodiment of the present invention. Upon receiving a request from a terminal, the virtual private network control device 10 registers the user in a communication service (step S101).
[0082] The terminal authenticates and connects to the communication network and starts communication (step S102). Subsequently, the virtual private network control device 10 acquires information about the virtual private network that will accommodate the user from the user profile session information (step S103).
[0083] In step S103, specifically, the user data processing unit 11 acquires the user profile included in the user data from the user database 20. The communication control information processing unit 13 acquires session information from the authentication and session control unit 40. As a result, the virtual private network control unit 10 acquires information on the virtual private network to which the user is to be accommodated from the user profile and session information.
[0084] Next, the virtual private network control device 10 determines whether or not connection to the virtual private network is permitted (step S104). If the virtual private network control device 10 determines that connection to the virtual private network is not permitted (step S104: NO), the process ends.
[0085] When the virtual private network control device 10 determines that connection to the virtual private network is permitted (step S104: YES), the virtual private network profile processing unit 12 acquires the virtual private network configuration profile from the virtual private network identification information (step S105).
[0086] Next, the virtual private network control device 10 determines whether or not a virtual private network can be constructed in the user access line / area (step S106). If the virtual private network control device 10 determines that a virtual private network cannot be constructed in the user access line / area (step S106: NO), the process ends.
[0087] When the virtual private network control device 10 determines that a virtual private network can be constructed in the user access line / area (step S106: YES), it acquires physical configuration information and physical device resource utilization information from the network configuration information management device 50 (step S107).
[0088] Specifically, in step S107, the physical network configuration processing unit 14 acquires physical configuration information from the network configuration information management device 50. Furthermore, the specific communication virtual private network management and monitoring unit 19 monitors the specific communication virtual private network to acquire physical device resource utilization information.
[0089] Next, the virtual private network control device 10 designs the configuration and allocation of physical device resources corresponding to the virtual private network configuration profile (step S108). Specifically, in step S108, the specific communication virtual private network design and configuration determination unit 15 designs the configuration of physical device resources corresponding to the virtual private network configuration profile. Also, the specific communication virtual private network deployment site and resource amount determination unit 16 determines the site where the virtual private network is deployed and the allocation amount of the necessary resources.
[0090] Next, the communication quality and network status determination unit 17 determines whether or not there are physical device resources that satisfy the virtual private network configuration profile requirements (step S109). If the communication quality and network status determination unit 17 determines that there are no physical device resources that satisfy the virtual private network configuration profile requirements (step S109: NO), the process ends.
[0091] When the communication quality / network status determination unit 17 determines that there are physical device resources that satisfy the virtual private network configuration profile requirements (step S109: YES), the specific communication virtual private network control instruction unit 18 instructs the transport device control management device 61 or server device control management device 71 of the target site to transfer data and processing logic based on the design results (step S110).
[0092] Next, the virtual private network control device 10, the transport device control management device 61 or the server device control management device 71 loads and starts the data transfer and processing logic (step S111), and the virtual private network control device 10 sets a transfer path between the data transfer and processing logic (step S112).
[0093] The data transfer and processing logic control unit 614 of the transport device control management device 61 or the data transfer and processing logic control unit 714 of the server device control management device 71 sets parameters to be used in processing the communication flow of the user for the activated data transfer and processing logic (step S113). The virtual private network control device 10 transfers the communication flow of the user to the activated virtual private network device (step S114).
[0094] <Example of this embodiment> 11 is a diagram illustrating an example in which an embodiment of the present invention is applied to a 5G network. The 5G network authenticates the terminal, performs session control to start communication, and establishes a communication path as a QoS flow within the 5G network. Then, in the process of establishing the QoS flow through the 5G network session control, the corresponding session control signal is transferred to the virtual private network control device 10 (1).
[0095] Next, the virtual private network control device 10 acquires the user profile using the session identifier included in the session control, and acquires information on the selected virtual private network of the user (2).
[0096] Then, based on the information on the selection of the virtual private network, the virtual private network control device 10 extracts the type of virtual private network to be configured, and obtains information indicating the conditions of the functional configuration of the virtual private network from the virtual private network configuration profile management device 30 (3).
[0097] The virtual private network control device 10 acquires physical network configuration information and current resource allocation information for the virtual private network from the network configuration information management device 50 (4). Next, the virtual private network control device 10 designs the data transfer and processing logic required for the corresponding communication flow, the hardware to which it is applied, and their configurations.
[0098] The virtual private network control device 10 transfers and activates data transfer and processing logic data to the target general-purpose server 73 / accelerator 74 / programmable switch 63 / white-box device 64 according to the design (6). The virtual private network control device 10 sets parameters required to process the communication flow of the terminal in accordance with the profile conditions of the corresponding user via the transport device control management device 61 or the server device control management device 71 (7).
[0099] In this way, data transfer processing is performed between the 5G network UPF and a virtual private network device (transport device or server device) that is executing processing according to the data transfer and processing logic, and a communication flow to the service is established.
[0100] <Hardware configuration> Finally, the hardware configuration of the virtual private network control device 10 according to this embodiment will be described. The virtual private network control device 10 according to this embodiment is realized, for example, by the hardware configuration of a computer 500 shown in Fig. 12. Note that the user database 20, virtual private network configuration profile management device 30, authentication / session control device 40, network configuration information management device 50, transport device control management device 61, server device control management device 71, etc. may also be realized by a similar hardware configuration.
[0101] 12 includes an input device 501, a display device 502, an external I / F 503, a communication I / F 504, a processor 505, and a memory device 506. Each of these pieces of hardware is connected to each other via a bus 507 so as to be able to communicate with each other.
[0102] The input device 501 is, for example, a keyboard, a mouse, a touch panel, etc. The display device 502 is, for example, a display, etc. Note that the computer 500 does not necessarily have to have at least one of the input device 501 and the display device 502.
[0103] The external I / F 503 is an interface with an external device such as a recording medium 503a. Examples of the recording medium 503a include a CD (Compact Disc), a DVD (Digital Versatile Disk), an SD memory card (Secure Digital memory card), and a USB (Universal Serial Bus) memory card.
[0104] The communication I / F 504 is an interface for performing data communication with other devices, equipment, systems, etc. The processor 505 is, for example, various types of arithmetic devices such as a CPU, etc. The memory device 506 is, for example, various types of storage devices such as an HDD, SSD, RAM (Random Access Memory), ROM (Read Only Memory), flash memory, etc.
[0105] The virtual private network control device 10 according to this embodiment can realize the various processes described above by having the hardware configuration of a computer 500 shown in Fig. 12. Note that the hardware configuration of the computer 500 shown in Fig. 12 is an example, and the computer 500 may have other hardware configurations. For example, the computer 500 may have multiple processors 505, or multiple memory devices 506.
[0106] The virtual private network control device 10 according to this embodiment realizes the processing functions required for the communication service at the timing of the start and end of communication, and allocates data transfer and processing logic to the hardware resources of the server device or transport device only for the time required while the user is using the service, thereby improving the utilization efficiency of hardware resources in the wireless communication network.
[0107] (Summary of the embodiment) This specification describes at least the virtual private network control device, wireless communication system, virtual private network control method, and program described in the following sections. (Section 1) a determination unit that determines a configuration of the virtualized network for each user in response to a request from the terminal, based on data related to a user of a communication service, information indicating attributes of the virtualized network for each user, information for controlling communication between the user and the terminal, and information indicating a configuration of a physical network; and a control instruction unit that instructs a device that controls a transport device that performs data transfer or a server device that performs processing to transfer logic for data transfer or processing to the transport device that performs data transfer or the server device that performs processing, based on the determined configuration of the network virtualized for each user. Virtual private network controller. (Section 2) the determination unit determines a base at which the virtualized network for each user is to be deployed and a required resource allocation amount as profile requirements that the virtualized network for each user should satisfy, and determines a configuration of the virtualized network for each user depending on whether there are resources of the transport device or the server device that satisfy the profile requirements, based on a network state or a communication quality state. 2. The virtual private network controller according to claim 1. (Section 3) The data relating to the user of the communication service includes any of information for uniquely identifying the user as a user ID and identifying the terminal being used, information for authenticating the user communicating on the network, information for identifying the line from which the access originates, information for identifying the area from which the terminal is accessed, information for identifying the location of the terminal, information indicating the service to which the user subscribes, information for identifying the virtual private network that provides a communication path to the subscribed service, and information for identifying or managing communications from the terminal. 2. The virtual private network controller according to claim 1. (Section 4) The information indicating the attributes of the virtualized network for each user includes any of the following: information for identifying the type of virtual private network to be designed or controlled; information indicating the logical network configuration; information indicating the configuration and application order of the data transfer and processing logic groups included in the virtual private network; information used to determine the area or access line that can be connected to the virtual private network by location, area, or line; information indicating the communication quality conditions for services on the virtual private network; information indicating the type of hardware resources that can be applied in the configuration of the virtual private network; and templates indicating typical resource deployment patterns or designs. 2. The virtual private network controller according to claim 1. (Section 5) A wireless communication system comprising a virtual private network control device and a device for controlling a transport device that performs data transfer or a server device that performs processing, The virtual private network controller comprises: a determination unit that determines a configuration of the virtualized network for each user in response to a request from the terminal, based on data related to a user of a communication service, information indicating attributes of the virtualized network for each user, information for controlling communication between the user and the terminal, and information indicating a configuration of a physical network; a control instruction unit that instructs a device that controls the transport device or the server device to transfer data or logic for processing to the transport device or the server device based on the determined configuration of the virtualized network for each user; The device controlling the transport device or the server device transfers the logic for the data transfer or processing for each session of the terminal when the terminal is connected to a network or when the virtualized network for each user is controlled, and includes a logic control unit that sets control information required for each session in order to set the content to be applied to each communication after the transferred logic for the data transfer or processing is activated. Wireless communication system. (Section 6) 1. A computer-implemented method for controlling a virtual private network, comprising: determining a configuration of the virtualized network for each user in response to a request from the terminal based on data related to the user of a communication service, information indicating attributes of the virtualized network for each user, information for controlling communication between the terminal and the user, and information indicating the configuration of a physical network; and instructing a device that controls the transport device or the server device to transfer logic for data transfer or processing to the transport device that performs data transfer or the server device that performs processing based on the determined configuration of the network virtualized for each user. Virtual private network control method. (Section 7) A program for causing a computer to function as each unit in the virtual private network control device described in any one of paragraphs 1 to 4.
[0108] Although the present embodiment has been described above, the present invention is not limited to such a specific embodiment, and various modifications and changes are possible within the scope of the gist of the present invention described in the claims. [Explanation of symbols]
[0109] 1. Wireless communication network 10 Virtual Private Network Controller 11 User data processing section 12 Virtual Private Network Profile Processing Unit 13 Communication control information processing section 14 Physical network configuration processing section 15. Virtual Private Network Design and Configuration Division for Specific Communications 16. Virtual Private Network Deployment Center for Specific Communications and Resource Amount Determination Unit 17 Communication quality and network status determination unit 18. Virtual Private Network Control Instructions for Specific Communications 19 Virtual Private Network Management and Monitoring Department for Specific Communications 20 User Database 21 User ID / Device Identification Information 22 Authentication Information 23 Access Line Identifier 24 Location Area Identifier 25 Location information 26 Subscription Service Information 27 Virtual Private Network Identification Information 28 Communication Session Information 29 Accommodating virtual private network control device identification information 30 Virtual Private Network Configuration Profile Management Device 31 Virtual Private Network Type Identification Information 32 Logical Topology Information 33 Data transfer, processing logic configuration, and sequence information 34 Applicable area / access line type information 35 Virtual Private Network Quality Conditions 36 Applied hardware resource type information 37 Resource Design Templates 40 Authentication and session control device 50 Network configuration information management device 51 Transport Physical Topology 52 Server Device Physical Topology 53 Transport equipment layout information 54 Server device location information 55 Transport device type information 56 Server device type information 57 Transport Device Physical Resource Information 58 Server device physical resource information 60 Transport Equipment Resource Pool 61 Transport Equipment Control and Management Equipment 611 Transport device control API function unit 612 Transport Device Status Management Unit 613 Transport Equipment Control Management Interface 614 Data transfer and processing logic control unit 62 Data Transfer and Processing Logic Repository 621 Data Transfer and Processing Logic Identification Information 622 Data Transfer and Processing Logic Information 63 Programmable Switch 64 White Box Device 70 Server Devices 71 Server device control management device 711 Server device control API function unit 712 Server device status management unit 713 Server Device Control Management IF Unit 714 Data transfer and processing logic control unit 72 Data Transfer and Processing Logic Repository 721 Data Transfer and Processing Logic Identification Information 722 Data Transfer and Processing Logic Information 73 General-purpose servers 74 Accelerator 500 computers 501 Input Device 502 Display device 503 External I / F 503a Recording media 504 Communication I / F 505 processor 506 Memory Device 507 Bus
Claims
1. a determination unit that determines a configuration of the virtualized network for each user in response to a request from the terminal, based on data related to a user of a communication service, information indicating attributes of the virtualized network for each user, information for controlling communication between the user and the terminal, and information indicating a configuration of a physical network; a control instruction unit that instructs a device that controls a transport device that performs data transfer or a server device that performs processing to transfer logic for data transfer or processing to the transport device that performs data transfer or the server device that performs processing, based on the determined configuration of the network virtualized for each user; the determination unit determines a base at which the virtualized network for each user is to be deployed and a required resource allocation amount as profile requirements that the virtualized network for each user should satisfy, and determines a configuration of the virtualized network for each user depending on whether there are resources of the transport device or the server device that satisfy the profile requirements. Virtual private network controller.
2. The data relating to the user of the communication service includes any of information for uniquely identifying the user as a user ID and for identifying the terminal being used, information for authenticating the user communicating on the network, information for identifying the line from which the access originates, information for identifying the area in which the terminal is located, information for identifying the location of the terminal, information indicating the service to which the user subscribes, information for identifying the virtual private network that provides a communication path to the subscribed service, and information for identifying or managing communications from the terminal.
2. The virtual private network controller of claim 1.
3. The information indicating the attributes of the virtualized network for each user includes any of the following: information for identifying the type of virtual private network to be designed or controlled; information indicating the logical network configuration; information indicating the configuration and application order of the data transfer / processing logic group included in the virtual private network; information used to determine the area or access line that can be connected to the virtual private network via a location, area, or line; information indicating the communication quality conditions for services on the virtual private network; information indicating the type of hardware resources that can be applied in the configuration of the virtual private network; and templates indicating typical resource deployment patterns or designs.
2. The virtual private network controller of claim 1.
4. A wireless communication system comprising a virtual private network control device and a device for controlling a transport device that performs data transfer or a server device that performs processing, The virtual private network controller comprises: a determination unit that determines a configuration of the virtualized network for each user in response to a request from the terminal, based on data related to a user of a communication service, information indicating attributes of the virtualized network for each user, information for controlling communication between the user and the terminal, and information indicating a configuration of a physical network; a control instruction unit that instructs a device that controls the transport device or the server device to transfer data or logic for processing to the transport device or the server device based on the determined configuration of the virtualized network for each user; The device controlling the transport device or the server device transfers the logic for the data transfer or processing for each session of the terminal when the terminal is connected to a network or when the virtualized network for each user is controlled, and includes a logic control unit that sets control information required for each session in order to set the content to be applied to each communication after the transferred logic for the data transfer or processing is activated. Wireless communication system.
5. 1. A computer-implemented method for controlling a virtual private network, comprising: a determination step of determining a configuration of the virtualized network for each user in response to a request from the terminal, based on data related to a user of a communication service, information indicating attributes of the virtualized network for each user, information for controlling communication between the terminal and the user, and information indicating a configuration of a physical network; and instructing a device that controls the transport device or the server device to transfer logic for data transfer or processing to the transport device that performs data transfer or the server device that performs processing, based on the determined configuration of the network virtualized for each user; the determining step determines a base at which the virtualized network for each user is to be deployed and a required resource allocation amount as profile requirements that the virtualized network for each user must satisfy, and determines a configuration of the virtualized network for each user depending on whether there are resources of the transport device or the server device that satisfy the profile requirements; Virtual private network control method.
6. A program for causing a computer to function as each unit in the virtual private network control device according to any one of claims 1 to 3.
Citation Information
Patent Citations
Quantum encryption communication system and method based on software defined network and slices
CN114465723A
Virtual network allocating method and device
JP2016054451A
Systems and methods for providing customized virtual wireless networks based on automatic service-oriented network creation
JP2018500817A
System and method for placing a virtual serving gateway for mobility management
JP2018506873A
Method and apparatus for customer service management for wireless communication networks
JP2018521564A