Method and apparatus for resource isolation on communication network
The method addresses the challenge of resource isolation in communication networks by standardizing the exchange of isolation and security requirements between 5G/6G networks and cloud-native infrastructure, ensuring robust security and isolation in multi-vendor and multi-cloud environments.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-06
- Publication Date
- 2026-04-02
AI Technical Summary
Current communication systems, such as 3GPP and 5G, face challenges in isolating communication resources effectively due to a lack of coordination between 3GPP systems and cloud/virtualization systems, leading to inadequate isolation of Virtual Network Functions/Cloud Native Network Functions in virtualization and physical layers, which can compromise security.
A method and apparatus for resource isolation on communication networks that involve exchanging isolation and security requirements between 5G/6G networks and cloud-native infrastructure in a standardized manner, using parameters to manage and allocate resources that satisfy strict isolation requirements, including hardware nodes, virtual machine nodes, infrastructure clusters, and namespaces.
Ensures effective resource isolation and security in multi-vendor and multi-cloud scenarios, preventing unauthorized access and data exposure, thereby enhancing the security and isolation of network functions in virtualization infrastructure.
Smart Images

Figure CN2023130026_02042026_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR RESOURCE ISOLATION ON COMMUNICATION NETWORKTECHNICAL FIELD
[0001] Various example embodiments of the present disclosure relate generally to the technology of communication, and in particular to a method and apparatus for resource isolation on communication network.BACKGROUND
[0002] In current communication system, such as the 3rd generation partnership project (3GPP) the 5th generation (5G) , new radio (NR) , network slicing enables enterprises and operators to address specific requirements, including security requirements coming from different market segments.
[0003] Some communication resources need to be isolated from each other, since a compromised or malicious low security profiled usage may impact a highly sensitive usage breaching isolation and / or access control.
[0004] However, as lack of coordination between 3GPP system and cloud / virtualization system, the Virtual Network Functions / Cloud Native Network Functions (VNF / CNF) serving different application may not be correctly isolated in virtualization and physical layers.SUMMARY
[0005] This summary is provided to introduce some aspects in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0006] Certain aspects of the present disclosure and their embodiments may provide solutions to these or other challenges. There are, proposed herein, various embodiments which address one or more of the issues disclosed herein. Specific method and apparatus for resource isolation on communication network may be provided.
[0007] A first aspect of the present disclosure provides a method performed by a first node for managing resources for a communication network. The method comprises: receiving, from a second node, a first request for communication resources, the first request including: a first parameter indicating isolation requirements for the communication resources; and transmitting, to the second node, a first response indicating the communication resources satisfying the isolation requirements for the communication resources.
[0008] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0009] In exemplary embodiments of the present disclosure, the communication resources comprise a managed object instance (MOI) for a collection of network functions (NF) ; and / or the virtual machine node is hardened or not; and / or the infrastructure cluster comprises a container orchestrator cluster.
[0010] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirements; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0011] In exemplary embodiments of the present disclosure, the method further comprises: transmitting, to a third node, a second request for an infrastructure cluster, the second request includes at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter; and receiving, from the third node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.
[0012] In exemplary embodiments of the present disclosure, the second request is for creating a new infrastructure cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster.
[0013] In exemplary embodiments of the present disclosure, the third node comprises at least one of: a container infrastructure service cluster management (CCM) , a management and orchestration (MANO) , a cloud manager, or a cloud service producer.
[0014] In exemplary embodiments of the present disclosure, the method further comprises: selecting an existing infrastructure cluster, when the existing infrastructure cluster satisfies an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter.
[0015] In exemplary embodiments of the present disclosure, the method further comprises: transmitting, to a fourth node, a third request to deploy workloads for the communication resources, the third request including at least one of: the first parameter, the first parameter and the second parameter, and / or the isolation requirements for the communication resources indicated by the first parameter or by the first parameter and the second parameter; and receiving, from the fourth node, a third response including addresses for the workloads.
[0016] In exemplary embodiments of the present disclosure, the third request further comprises: network security policies, and / or an identifier of a namespace.
[0017] In exemplary embodiments of the present disclosure, the fourth node comprises at least one of: a container infrastructure service management (CISM) , a K8s control plane or a k8s apiserver.
[0018] In exemplary embodiments of the present disclosure, the method further comprises: transmitting, to a fifth node, a fourth request for creating a network service, the fourth request including at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the network service indicated by the first parameter or by the first parameter and the second parameter; and receiving, from the fifth node, a fourth response indicating the network service satisfying the isolation requirement on the network service and infrastructure resources for communication resources.
[0019] In exemplary embodiments of the present disclosure, the method further comprises: transmitting, to a fifth node, a fifth request for allocating infrastructure nodes for a cluster; and linking infrastructure nodes together for a cluster, a cloud manager, or a cloud service producer.
[0020] In exemplary embodiments of the present disclosure, the fifth node comprises: a management and orchestration (MANO) , a cloud manager, or a cloud service producer.
[0021] In exemplary embodiments of the present disclosure, the first node comprises: a Network Slice Subnet Management Service Producer (NSSMS_P) ; and the second node comprises: a Network Slice Subnet Management Service Consumer (NSSMS_C) .
[0022] A second aspect of the present disclosure provides a method performed by a third node for managing resources for a communication network. The method comprises: receiving, from a first node or a fifth node, a second request for an infrastructure cluster, the second request including a first parameter, or an isolation requirement on the infrastructure cluster indicated by the first parameter; and transmitting, to the first node or the fifth node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.
[0023] In exemplary embodiments of the present disclosure, the first parameter further indicates: an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / or an isolation requirement on a namespace or not.
[0024] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirement on the infrastructure cluster; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0025] In exemplary embodiments of the present disclosure, the third node creates a new infrastructure cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster; or the third node assigns an existing CIS cluster.
[0026] In exemplary embodiments of the present disclosure, the method further comprises: transmitting, to the fifth node, a fifth request for allocating infrastructure resources for the infrastructure cluster, the fifth request including the first parameter, or an isolation requirement on the infrastructure resources indicated by the first parameter; and receiving, from the fifth node, a fifth response indicating the infrastructure resources for the infrastructure cluster satisfying the isolation requirement on the infrastructure resources.
[0027] In exemplary embodiments of the present disclosure, the fifth node comprises: a MANO, a cloud manager, or a cloud service producer.
[0028] In exemplary embodiments of the present disclosure, the first node comprises: a NSSMS_P; and the third node comprises at least one of: a CCM, a MANO, a cloud manager, or a cloud service producer.
[0029] A third aspect of the present disclosure provides a method performed by a fourth node for managing resources for a communication network. The method comprises: receiving, from a first node or a fifth node, a third request to deploy workloads for communication resources, the third request including: isolation requirements for the communication resources, and / or a first parameter indicating the isolation requirements for the communication resources; and transmitting, to the first node or the fifth node, a third response including addresses for the workloads.
[0030] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / or an isolation requirement on a namespace or not.
[0031] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirements; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0032] In exemplary embodiments of the present disclosure, the third request further comprises: network security policies, and / or an identifier of a namespace.
[0033] In exemplary embodiments of the present disclosure, the first node comprises: a NSSMS_P. The fourth node comprises at least one of: a CISM, a K8s control plane or a k8s apiserver; and the fifth node comprises at least one of: a MANO, a cloud manager, or a cloud service producer.
[0034] A fourth aspect of the present disclosure provides a method performed by a fifth node for managing resources for a communication network. The method comprises: receiving, from a first node or a third node, a fifth request for allocating infrastructure resources for an infrastructure cluster, the fifth request including a first parameter, or isolation requirements for the communication resources indicated by the first parameter; and transmitting, to the first node or the third node, a fifth response indicating infrastructure resources for the infrastructure cluster satisfying the isolation requirements for the communication resources.
[0035] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirements; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0036] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / or an isolation requirement on a namespace or not.
[0037] In exemplary embodiments of the present disclosure, the third node comprises: a CCM; and the fifth node comprises at least one of: a MANO, a cloud manager, or a cloud service producer.
[0038] A fifth aspect of the present disclosure provides a method performed by a fifth node for managing resources for a communication network. The method comprises: receiving, from a first node, a fourth request for creating a network service, the fourth request including a first parameter indicating isolation requirements for infrastructure resources providing the network service; and transmitting, to the first node, a fourth response indicating the network service and the infrastructure resources satisfying the isolation requirements.
[0039] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0040] In exemplary embodiments of the present disclosure, the communication resources comprise a MOI for a NF. The virtual machine node is hardened or not; and / or the infrastructure cluster comprises a container orchestrator cluster.
[0041] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirement; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0042] In exemplary embodiments of the present disclosure, the method further comprises: transmitting, to a third node, a second request for an infrastructure cluster, the second request includes at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter; and receiving, from the third node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.
[0043] In exemplary embodiments of the present disclosure, the second request is for creating a new infrastructure cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster.
[0044] In exemplary embodiments of the present disclosure, the third node comprises: a container infrastructure service cluster management, CCM.
[0045] In exemplary embodiments of the present disclosure, the method further comprises: selecting an existing infrastructure cluster, when the existing infrastructure cluster satisfies an isolation requirement on the infrastructure cluster indicated by the first parameter, or by the first parameter and the second parameter.
[0046] In exemplary embodiments of the present disclosure, the method further comprises: transmitting, to a fourth node, a third request to deploy workloads over the communication resources, the third request including at least one of: the first parameter, the first parameter and the second parameter, and / or the isolation requirements for the communication resources indicated by the first parameter or by the first parameter and the second parameter; and receiving, from the fourth node, a third response including addresses for the workloads.
[0047] In exemplary embodiments of the present disclosure, the third request further comprises: network security policies, and / or an identifier of a namespace.
[0048] In exemplary embodiments of the present disclosure, the fourth node comprises: a CISM.
[0049] In exemplary embodiments of the present disclosure, the first node comprises: a NSSMS_P; and the fifth node comprises: a MANO, a cloud manager, or a cloud service producer.
[0050] A sixth aspect of the present disclosure provides a first node comprising means configured for: receiving, from a second node, a first request for communication resources, the first request including: a first parameter indicating isolation requirements for the communication resources; and transmitting, to the second node, a first response indicating the communication resources satisfying the isolation requirements for the communication resources. The means comprise: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the performance of the first node.
[0051] In exemplary embodiments of the present disclosure, the means are further configured for performing the method according to any of the embodiments of the first aspect.
[0052] A seventh aspect of the present disclosure provides a third node comprising means configured for: receiving, from a first node or a fifth node, a second request for an infrastructure cluster, the second request including a first parameter, or an isolation requirement on the infrastructure cluster indicated by the first parameter; and transmitting, to the first node or the fifth node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster. The means comprise: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the performance of the third node.
[0053] In exemplary embodiments of the present disclosure, the means are further configured for performing the method according to any of the embodiments of the second aspect.
[0054] An eighth aspect of the present disclosure provides a fourth node comprising means configured for: receiving, from a first node or a fifth node, a third request to deploy workloads for communication resources, the third request including: isolation requirements for the communication resources, and / or a first parameter indicating the isolation requirements for the communication resources; and transmitting, to the first node or the fifth node, a third response including addresses for the workloads. The means comprise: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the performance of the fourth node.
[0055] In exemplary embodiments of the present disclosure, the means are further configured for performing the method according to any of the embodiments of the third aspect.
[0056] A ninth aspect of the present disclosure provides a fifth node comprising means configured for: receiving, from a first node or a third node, a fifth request for allocating infrastructure resources for an infrastructure cluster, the fifth request including a first parameter, or isolation requirements for the communication resources indicated by the first parameter; and transmitting, to the first node or the third node, a fifth response indicating infrastructure resources for the infrastructure cluster satisfying the isolation requirements for the communication resources. The means comprise: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the performance of the fifth node.
[0057] In exemplary embodiments of the present disclosure, the means are further configured for performing the method according to any of the embodiments of the fourth aspect.
[0058] A tenth aspect of the present disclosure provides a fifth node comprising means configured for: receiving, from a first node, a fourth request for creating a network service, the fourth request including a first parameter indicating isolation requirements for infrastructure resources providing the network service; and transmitting, to the first node, a fourth response indicating the network service and the infrastructure resources satisfying the isolation requirements. The means comprise: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the performance of the fifth node.
[0059] In exemplary embodiments of the present disclosure, the means are further configured for performing the method according to any of the embodiments of the fifth aspect.
[0060] An eleventh aspect of the present disclosure provides a computer-readable storage medium storing instructions, which when executed by at least one processor of a node, cause the at least one processor of the node to perform the method according to any of the embodiments of the first, second, third, fourth, and fifth aspects.
[0061] A twelfth aspect of the present disclosure provides an apparatus. The apparatus comprises: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to perform the method according to any of embodiments of the first, second, third, fourth, and fifth aspects.
[0062] In exemplary embodiments of the present disclosure, the apparatus is or is comprised in a node.
[0063] Embodiments herein afford many advantages. According to embodiments of the present disclosure, an improved manner for resource isolation on network slicing may be provided.
[0064] According to embodiments of the present disclosure, the exemplary embodiments of the present disclosure propose a mechanism that allows to exchange isolation and security requirements of communication resources (such as network slice subnet / network functions, NSS / NF (s) ) between 5th generation / 6th generation (5G / 6G) network and cloud-native infrastructure in standard way, hence fulfill security and isolation requirements of 5G / 6G network in virtualization infrastructure, even in multi-vendor and multi cloud service provider scenarios.BRIEF DESCRIPTION OF DRAWINGS
[0065] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more fully apparent, by way of example, from the following detailed description with reference to the accompanying drawings, in which like reference numerals or letters are used to designate like or equivalent elements. The drawings are illustrated for facilitating better understanding of the embodiments of the disclosure and not necessarily drawn to scale, in which:
[0066] FIG. 1 is a diagram showing an exemplary manner to deploy cloud-native NFs with more MNO control.
[0067] FIG. 2 is a diagram showing an exemplary manner to deploy cloud-native NFs with more CSP control.
[0068] FIG. 3 is an exemplary diagram showing an isolation in network resource layer.
[0069] FIG. 4A is a flow chart showing a method performed by a first node, according to exemplary embodiments of the present disclosure.
[0070] FIG. 4B is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0071] FIG. 4C is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0072] FIG. 4D is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0073] FIG. 4E is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0074] FIG. 4F is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0075] FIG. 5A is a flow chart showing a method performed by a third node, according to exemplary embodiments of the present disclosure.
[0076] FIG. 5B is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.
[0077] FIG. 6 is a flow chart showing a method performed by a fourth node, according to exemplary embodiments of the present disclosure.
[0078] FIG. 7 is a flow chart showing a method performed by a fifth node, according to exemplary embodiments of the present disclosure.
[0079] FIG. 8A is a flow chart showing a method performed by a fifth node, according to exemplary embodiments of the present disclosure.
[0080] FIG. 8B is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0081] FIG. 8C is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0082] FIG. 8D is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0083] FIG. 9 is an exemplary diagram showing a generic workflow to handle the isolation parameter.
[0084] FIG. 10A is a diagram showing an exemplary signal flow of deployment option 1.
[0085] FIG. 10B is a diagram showing some adjustments for the FIG. 10B.
[0086] FIG. 11 is a diagram showing an exemplary signal flow of deployment option 2.
[0087] FIG. 12 is a block diagram showing an exemplary structure for a first node, according to exemplary embodiments of the present disclosure.
[0088] FIG. 13 is a block diagram showing an exemplary structure for a third node, according to exemplary embodiments of the present disclosure.
[0089] FIG. 14 is a block diagram showing an exemplary structure for a fourth node, according to exemplary embodiments of the present disclosure.
[0090] FIG. 15 is a block diagram showing an exemplary structure for a fifth node, according to exemplary embodiments of the present disclosure.
[0091] FIG. 16 is a block diagram showing an apparatus / computer readable storage medium, according to embodiments of the present disclosure.
[0092] FIG. 17 is a block diagram showing exemplary apparatus units for a first node, which is suitable for performing the method according to embodiments of the disclosure.
[0093] FIG. 18 is a block diagram showing exemplary apparatus units for a third node, which is suitable for performing the method according to embodiments of the disclosure.
[0094] FIG. 19 is a block diagram showing exemplary apparatus units for a fourth node, which is suitable for performing the method according to embodiments of the disclosure.
[0095] FIG. 20 is a block diagram showing exemplary apparatus units for a fifth node, which is suitable for performing the method according to embodiments of the disclosure.DETAILED DESCRIPTION
[0096] The embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for better understanding, rather than limitations on the scope of the present disclosure. The described features, advantages, and characteristics of the disclosure may be combined in any suitable manner in one or more embodiments.
[0097] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless clearly given and / or implied from the context. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate.
[0098] As used herein, the term “network” or “communication network” refers to a network following any suitable communication standards (such for an internet network, or any wireless network) . For example, wireless communication standards may comprise WLAN (Wireless Local Area Network) , new radio (NR) , long term evolution (LTE) , LTE-Advanced, 5G NR, etc. In the following description, the terms “network” and “system” can be used interchangeably.
[0099] The term “node” refers to a computing device or computing entity or computing function or any other devices (physical or virtual) in a communication network. For example, the node in the network may include a base station (BS) , an access point (AP) , or any other suitable device in a wireless communication network. The BS may be, for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , a next generation NodeB (gNodeB or gNB) , a remote radio unit (RRU) , a radio header (RH) , a remote radio head (RRH) , a relay, a low power node such as a femto, a pico, and so forth. Further, the node may include: NSSMS_P, NSSMS_C, CCM, CISM, MANO, etc.
[0100] The term “terminal device” refers to any end device that can access a communication network and receive services therefrom. By way of example and not limitation, the terminal device refers to a mobile terminal, user equipment (UE) , a non-AP device (such as a non-AP Station (STA) ) , or other suitable devices. The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, a wearable device, a vehicle-mounted wireless terminal device, a vehicle, and the like.
[0101] As one example, a terminal device may represent a device configured for communication in accordance with one or more communication standards promulgated by any standard organization, such as 3rd generation partnership project, 3GPP.
[0102] As yet another example, in an Internet of Things (IoT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another terminal device and / or network equipment. Particular examples of such machines or devices are sensors, metering devices such as power meters, industrial machinery, or home or personal appliances, for example refrigerators, televisions, personal wearables such as watches etc. In other scenarios, a terminal device may represent a vehicle or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.
[0103] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.
[0104] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0105] Exemplary embodiments of the disclosure are relevant to a method and an apparatus for resource isolation on communication network.
[0106] Cloud native technology is adopted in 5th generation / 6th generation (5G / 6G) networks. During 4th generation-5th generation (4G-5G) transition, the core network was transitioned from traditional point-to-point protocols towards a Service Based Architecture (SBA) . Such transition represented a major step towards a cloud-native network architecture. Multi-cloud-nativeness will be adopted in 6th generation system (6GS) , including both cloudified core and access networks, to enable flexible deployment of the 6GS in heterogenous (i.e., centralized, distributed, multi-stakeholder) cloud environments and to take full benefit of their possibilities. By embracing a cloud native approach for the deployment of the 5G / 6G, telecommunication providers can unlock numerous advantages. One of the key benefits is the ability to leverage the inherent scalability of cloud environments, allowing for seamless expansion and adaptation to evolving demands. Additionally, cloud native architectures enable the integration of advanced technologies such as artificial intelligence and machine learning, empowering telcos to deliver more intelligent and autonomous services. The inherent resilience of cloud native systems enhances the reliability and fault tolerance of the 5G / 6G, ensuring high availability and minimizing disruptions. On the other hand, adoption of cloud native principles implies sharing hardware resource, even OS (operating system) kernel, between 5G / 6G NFs (network functions) .
[0107] Cloud-native technologies are developed in various standardization organizations, such as European Telecommunications Standards Institute (ETSI ) , Network Functions Virtualization (NFV ) , 3rd Generation Partnership Project (3GPP ) . E. g., ETSI NFV developed / is developing a series of cloud-native specification in Release 4 (REL4) which referring to the Cloud Native Computing Foundation (CNCF) (e.g. kubernetes) , OpenStack, Open Container Initiative (OCI ) , etc. ETSI also extends existing information model to support cloud-native NFs (Network Function) . Services and System Aspects 5 (3GPP SA5 ) had Release 18 (R18) Study Item &Work Item (SI&WI ) on cloud-native management, and there’s a Release 19 (R19) Study Item Description (SID ) proposal submitted to SA5 workshop. The main venues of cloud-native are Open Source, e.g. CNCF which develops several de-facto cloud-native “standard” such as Kubernetes, Isito etcd, OpenStack, Nephio, etc. Many cloud service providers, such as Microsoft, Amazon Web Service (AWS ) , Google, Alibaba, etc, provide cloud-native services. All of those organizations also develop / provide solutions to isolate and protect workload deployed in the virtualization infrastructure. In addition, there’ re security dedicated organizations, e.g. Cloud Security Alliance (CSA ) , Center for Internet Security (CIS) , Common and Internal Spanning Tree (CIST) , etc., define requirements / guidelines for cloud-native security.
[0108] There are two typical scenarios to deploy cloud-native NFs (Network Function) , e.g., allocate virtual resource for a collection of NFs or NSS (Network Slice Subnet) .
[0109] FIG. 1 is a diagram showing an exemplary manner to deploy cloud-native NFs with more MNO control.
[0110] The scenario shown in FIG. 1 has more mobile network operator (MNO) control. In this case, the operation supporting system (OSS) communicates to container infrastructure service (CIS) cluster management (CCM) to create / scale / update CIS cluster for an NSS (network slice subnet) / collection of NFs, and communicates with CIS management (CISM) to deploy workloads (e.g., constituted cloud-native NFs of an NSS / collection of NFs) .
[0111] In step 1 of the FIG. 1, the operation supporting system (OSS) communicates to container infrastructure service (CIS) cluster management (CCM) to create / scale / update CIS cluster for an network slice subnet (NSS) / collection of NFs. The Request from the OSS may include: CIS Cluster Descriptor (CCD) .
[0112] In step 2, the CCM communicates to MANO (and / or, Network Function Virtualization Orchestration (NFVO) / Virtual Network Function Manager (VNFM) / Virtual Infrastructure management (VIM) ) to deploy infrastructure. The request from the CCM may include: CIS Cluster Node Descriptors (CCND) , and / or CIS Cluster Node Resource Descriptor (CCNRD) .
[0113] In step 3, the CCM communicates to CISM to install required tools. The request from the CCM my include: CCND.
[0114] In step 4, the CCM communicates to CISM to start control plane.
[0115] In step 5, the CCM communicates to CISM to set up cluster configuration (users, api-server, open ports) .
[0116] In step 6, the CCM communicates to MANO to configure infrastructure properties. The communication between the CCM and the MANO includes CCD.
[0117] In step 7, the CCM responds to the OSS with CIS cluster id, CISM_address.
[0118] In step 8, the OSS communicates to CISM to deploy workload. The request from OSS includes Managed Container Infrastructure Object Descriptors (MCIO D) .
[0119] In step 9, the CISM manages the CIS_instance, i.e., assigns and configures resource for workload.
[0120] In step 10, the CISM responds to OSS with address of Managed Container Infrastructure Object (MCIO) , with namespace or not.
[0121] In step 11, the OSS communicates to CIS_instance with NF configuration.
[0122] FIG. 2 is a diagram showing an exemplary manner to deploy cloud-native NFs with more CSP control.
[0123] The scenario shown in FIG. 2 has more cloud service provider (CSP) control. In this case, the OSS (operation supporting system) calls virtualization management and orchestration system (e.g. NFV Management and Orchestration (MANO) ) to create a virtualized network service which may trigger MANO to communicate with CCM to create / scale / update CIS cluster for the network service, and communicate with CISM to deploy constituted VNFs of the network service.
[0124] In step 1 of the FIG. 2, the operation supporting system (OSS) communicates to MANO to create NS. The Request from the OSS may include: Virtual Network Function Descriptors, Network Service Descriptor (VNFDs, NSD) .
[0125] In step 2, the MANO communicates to CCM to deploy CIS cluster. The request from MANO includes CCD.
[0126] In step 3, the MANO communicates with CCM to deploy infrastructure. The communication between MANO and CCM includes CCND, and / or CCNRD.
[0127] In step 4, the CCM communicates to CISM to install required tools. The request from the CCM my include: CCND.
[0128] In step 5, the CCM communicates to CISM to start control plane.
[0129] In step 6, the CCM communicates to CISM to set up cluster configuration (users, api-server, open ports) .
[0130] In step 7, the CCM communicates with MANO to configure infrastructure properties. The communication between the CCM and the MANO includes CCD.
[0131] In step 8, the CCM responds to the MANO with CIS cluster id, CISM_address.
[0132] In step 9, the MANO communicates to CISM to deploy workload. The request from OSS include MCIO D.
[0133] In step 10, the CISM manages the CIS_instance, i.e., assigns and configures resource for workload.
[0134] In step 11, the CISM responds to MANO with address of MCIO, with namespace or not.
[0135] In step 12, the MANO responds to OSS with NS, VNF, etc.
[0136] In step 13, the OSS communicates to CIS_instance with NF configuration.
[0137] Resource isolation for network slice and network slice subnet will be further illustrated below. 5G / 6G will be able to support extreme and diverse requirements for throughput, latency, availability, capacity. Security is another fundamental network requirement that needs to be optimized for each specific use case, especially for those uses cases where security becomes critical (e.g., V2X (vehicle to everything) platooning, enterprise Virtual Private Network (VPN ) or Electric grids) . Operator will allocate 5G / 6G network resources to vertical / enterprise customers to support various use cases and applications, and the allocated resource can be isolated from networks or network resources used by other cellular customers. The network resources are isolated from logic network layer (e.g. network slice) , a set of NFs / resource layer (e.g. network slice subnet, or network slice instance) , virtualization layer (e.g. VNF, Cloud Native Function (CNF) ) , physical layer (e.g. physical server, Radio Frequency (RF) ) . Also, as the sensitivity of different NFs in 5G / 6G network can be different, isolation between the NFs allocated to same vertical customer or for same business case may be also required.
[0138] Network slicing is a key feature and business driver for 5G, which enables enterprises and operators to address specific requirements of different market segments (e.g., industrial, smart cities, healthcare, automotive) . The overall security architecture of 5G network is enhanced with new security features, available as well in network slices as logical networks created within the 5G network. With the corresponding slice specific enforcements, slice security isolation can prevent unauthorized access and modification to data, processes, services or functions.
[0139] FIG. 3 is an exemplary diagram showing an isolation in network resource layer.
[0140] Slice isolation is also developed in other 3GPP groups. Different examples of resource isolation between slices for different UEs are given below.
[0141] ● A slice can be fully isolated from other slices, in a path from radio access network (RAN) to transport link / layer and then to core network (CN) , and in both control plane and user plane. Thus, dedicated resources are allocated to the slice, e.g., S-NSSAI (Single Network Slice Selection Assistance Information) #1.
[0142] ● A slice can be partially isolated from other slices. E. g., distributed unit (DU) and other control plane (CP) network functions (NFs) may be shared, but dedicated user plane (UP) related NFs are used for, e.g., S-NSSAI#3.
[0143] ● A slice can share all NFs with other slices. E. g., DU, centralized Unit (CU) , CP and UP NFs may be shared for, e.g., S-NSSAI#4 and #5.
[0144] Further, e.g., management plane expects isolate resources of apps in S-NSSAI#3 from apps in S-NSSAI#4 and S-NSSAI#5, and correctly configured network slice information (NSIs) and S-NSSAIs in NFs, which may cause the NFs (in user plane) in S-NSSAI#4 and #5 being isolated from NF Services of NFs in S-NSSAI#3.
[0145] Patent application PCT / CN2023 / 112984 of the same applicant proposed a solution on how to map the isolation requirements of a network slice to configuration of NFs, limit interaction between the NFs belong to different isolation group, enable route UE signaling message to right control plane (CP) NFs and user traffic to right UPF without compromising isolation requirement. With the enhancement of PCT / CN2023 / 112984, the isolation of network slice can be enforced at network function (NF) layer of 5G network as shown in FIG. 3.
[0146] PCT / CN2023 / 112984 enhanced 5G network resource model (NRM) to include security requirements / criteria in slice profile of network slice subnet (NSS) which can be used to select and configure NFs. It also introduced leaf NSS which is a collection of NFs to be deployed to virtualization infrastructure, and the NFs in the collection share same security properties and also can share same virtualization resources.
[0147] PCT / CN2023 / 112984 proposed a solution on how to map the isolation requirements of a network slice to configuration of NFs, limit interaction between the NFs belong to different isolation group, enable route UE signaling message to right control plane (CP) NFs and user traffic to right UPF without compromising isolation requirement. With the enhancement of PCT / CN2023 / 112984, the isolation of network slice can be enforced at network function (NF) layer of 5G network.
[0148] ETSI NFV developed a series of cloud-native specification in REL4 which referring to the CNCF (e.g. kubernetes) , OpenStack, OCI, etc. As shown above, the reports and specs (e.g., ETSI NFV –(IFA) 029, IFA036, IFA043, etc. ) defined interfaces and workflow to deploy cloud-native NFs to virtualization infrastructure, which also introduced a few descriptors / profiles to express the requirements of the workload. However, how to fulfill security and isolation requirements of 5G network in virtualization infrastructure was not covered by those specification, neither in aforementioned open source projects.
[0149] ETSI NFV SEC023 and 3GPP TR (technical report) 33.848 (V18.0.0 (2023-09) ) raised requirements for 3GPP resource and network slice isolation, and listed potential technologies to support resource isolation in virtualization infrastructure. However, the technical reports didn’ t cover how to fulfill security and isolation requirements of 5G network in infrastructure.
[0150] The current disclosure introduces a mechanism to exchange isolation and security requirements of NSS / NF (s) between 5G / 6G network and cloud-native infrastructure in standard way, hence fulfill security and isolation requirements of 5G / 6G network in virtualization infrastructure in multi-vendor and multi cloud service provider scenarios.
[0151] Operator may allocate virtual network and network resource to specific vertical applications with using network slicing, and expect the resources are isolated for application based on corresponding policies and existing isolation solutions in network. However, as lack of coordination between 3GPP system and cloud / virtualization system, the VNF / CNF serving different application may not be correctly isolated in virtualization and physical layers. It’s even worse in edge computing scenario where operator’s NFs may deploy with applications of verticals, and different NFs for same application may be deployed in virtualization infrastructure of different CSPs.
[0152] Without proper isolation and security control in cloudified environment, sensitive data of one network slice could be exposed to network functions running in other network slices through side channel attacks, although the access control is correctly performed on SBI based 5GC network.
[0153] The current disclosure introduces a mechanism to exchange isolation and security requirements of NSS / NF (s) between 5G / 6G network and cloud-native infrastructure in standard way, hence fulfill security and isolation requirements of 5G / 6G network in virtualization infrastructure, even in multi-vendor and multi cloud service provider scenarios.
[0154] FIG. 4A is a flow chart showing a method performed by a first node, according to exemplary embodiments of the present disclosure.
[0155] As shown in FIG. 4A, a first aspect of the present disclosure provides a method 400 performed by a first node for managing resources for a communication network. The method 400 comprises: a step S402, receiving, from a second node, a first request for communication resources, the first request including: a first parameter indicating isolation requirements for the communication resources; and a step S404, transmitting, to the second node, a first response indicating the communication resources satisfying the isolation requirements for the communication resources.
[0156] According to embodiments of the present disclosure, the isolation requirements for the communication resources may be represented by a first parameters, thus allows to exchange isolation and security requirements of communication resources (such as network slice subnet / network functions, NSS / NF (s) ) between 5th generation / 6th generation (5G / 6G) network and cloud-native infrastructure in standard way.
[0157] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0158] In exemplary embodiments of the present disclosure, the communication resources comprise a managed object instance, MOI, for a collection of network functions, NF; and / or the virtual machine node is hardened or not; and / or the infrastructure cluster comprises a container orchestrator cluster. The container orchestrator cluster may comprise: a container infrastructure service, CIS, cluster, and / or a K8s cluster.
[0159] According to embodiments of the present disclosure, the first parameter may be used to indicate the isolation requirement on any kind of communication resources.
[0160] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirements; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0161] According to embodiments of the present disclosure, the first parameter may have any applicable kind of value, such as numeric value, character string, enumerated value, list, array, etc.
[0162] FIG. 4B is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0163] As shown in FIG. 4B, in exemplary embodiments of the present disclosure, the method 400 further comprises: a step S406, transmitting, to a third node, a second request for an infrastructure cluster, the second request includes at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter; and a step S408, receiving, from the third node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.
[0164] According to embodiments of the present disclosure, the first parameter and / or the second parameter may be used for CIS cluster.
[0165] In exemplary embodiments of the present disclosure, the second request is for creating a new infrastructure cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster.
[0166] In exemplary embodiments of the present disclosure, the third node comprises: a container infrastructure service cluster management, CCM.
[0167] FIG. 4C is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0168] As shown in FIG. 4C, in exemplary embodiments of the present disclosure, the method 400 further comprises: a step S410, selecting an existing infrastructure cluster, when the existing infrastructure cluster satisfies an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter.
[0169] According to embodiments of the present disclosure, the first node may operate based on the isolation requirements indicated by the first parameter and / or the second parameter.
[0170] FIG. 4D is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0171] As shown in FIG. 4D, in exemplary embodiments of the present disclosure, the method 400 further comprises: a step S412, transmitting, to a fourth node, a third request to deploy workloads for the communication resources, the third request including at least one of: the first parameter, the first parameter and the second parameter, and / or the isolation requirements for the communication resources indicated by the first parameter or by the first parameter and the second parameter; and a step S414, receiving, from the fourth node, a third response including addresses for the workloads.
[0172] If the communication resource is NF / collection of NFs, the workload is deployed for supporting communication resource and the workload is deployed "in" the infrastructure.
[0173] According to embodiments of the present disclosure, the first node may use the first parameter and / or second parameter when deploying workloads.
[0174] In exemplary embodiments of the present disclosure, the third request further comprises: network security policies, and / or an identifier of a namespace.
[0175] In exemplary embodiments of the present disclosure, the fourth node comprises at least one of: a container infrastructure service management, CISM, a K8s control plane or a k8s apiserver.
[0176] FIG. 4E is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0177] As shown in FIG. 4E, in exemplary embodiments of the present disclosure, the method 400 further comprises: a step S416, transmitting, to a fifth node, a fourth request for creating a network service, the fourth request including at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the network service indicated by the first parameter or by the first parameter and the second parameter; and a step S418, receiving, from the fifth node, a fourth response indicating the network service satisfying the isolation requirement on the network service and infrastructure resources for communication resources, which are related to the network service.
[0178] FIG. 4F is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0179] As shown in FIG. 4E, in exemplary embodiments of the present disclosure, the method 400 further comprises: a step S406’ , transmitting, to a fifth node, a fifth request for allocating infrastructure nodes for a cluster; and a step S407’ , linking infrastructure nodes together for a cluster.
[0180] According to embodiments of the present disclosure, the first node may create / update a cluster by itself, instead of requesting a third node.
[0181] In exemplary embodiments of the present disclosure, the fifth node comprises at least one of:a management and orchestration, MANO, a cloud manager, or a cloud service producer.
[0182] In exemplary embodiments of the present disclosure, the first node comprises: a Network Slice Subnet Management Service Producer, NSSMS_P; and the second node comprises: a Network Slice Subnet Management Service Consumer, NSSMS_C.
[0183] It should be noted that the above specific exemplary entities, functions for the nodes are only examples for illustration. The above nodes may be different entities and / or functions according to the specific application scenarios.
[0184] FIG. 5A is a flow chart showing a method performed by a third node, according to exemplary embodiments of the present disclosure.
[0185] As shown in FIG. 5A, a second aspect of the present disclosure provides a method 500 performed by a third node for managing resources for a communication network. The method 500 comprises: a step S502, receiving, from a first node or a fifth node, a second request for an infrastructure cluster, the second request including a first parameter, or an isolation requirement on the infrastructure cluster indicated by the first parameter; and a step S504, transmitting, to the first node or the fifth node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the CIS cluster.
[0186] In exemplary embodiments of the present disclosure, the first parameter further indicates: an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / or an isolation requirement on a namespace or not.
[0187] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirement on the infrastructure cluster; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0188] In exemplary embodiments of the present disclosure, the third node creates a new CIS cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster; or the third node assigns an existing infrastructure cluster.
[0189] FIG. 5B is a flow chart showing further steps of the method as shown in FIG. 5A, according to exemplary embodiments of the present disclosure.
[0190] As shown in FIG. 5B, in exemplary embodiments of the present disclosure, the method 500 further comprises: a step S506, transmitting, to the fifth node, a fifth request for allocating infrastructures for the infrastructure cluster, the fifth request including the first parameter, or an isolation requirement on the infrastructures indicated by the first parameter; and a step S508, receiving, from the fifth node, a fifth response indicating the infrastructures for the infrastructure cluster satisfying the isolation requirement on the infrastructures.
[0191] In exemplary embodiments of the present disclosure, the fifth node comprises at least one of:a management and orchestration, MANO, a cloud manager, or a cloud service producer..
[0192] In exemplary embodiments of the present disclosure, the first node comprises: a Network Slice Subnet Management Service Producer, NSSMS_P; and the third node comprises at least one of: a container infrastructure service cluster management, CCM, a MANO, a cloud manager, or a cloud service producer.
[0193] FIG. 6 is a flow chart showing a method performed by a fourth node, according to exemplary embodiments of the present disclosure.
[0194] As shown in FIG. 6, a third aspect of the present disclosure provides a method 600 performed by a fourth node for managing resources for a communication network. The method 600 comprises: a step S602, receiving, from a first node or a fifth node, a third request to deploy workloads for communication resources, the third request including: isolation requirements for the communication resources, and / or a first parameter indicating the isolation requirements for the communication resources; and a step S604, transmitting, to the first node or the fifth node, a third response including addresses for the workloads.
[0195] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / or an isolation requirement on a namespace or not.
[0196] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirements; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0197] In exemplary embodiments of the present disclosure, the third request further comprises: network security policies, and / or an identifier of a namespace.
[0198] In exemplary embodiments of the present disclosure, the first node comprises: a Network Slice Subnet Management Service Producer, NSSMS_P. The fourth node comprises at least one of: a container infrastructure service management, CISM, a K8s control plane or a k8s apiserver; and the fifth node comprises at least one of: a management and orchestration, MANO, a cloud manager, or a cloud service producer.
[0199] FIG. 7 is a flow chart showing a method performed by a fifth node, according to exemplary embodiments of the present disclosure.
[0200] As shown in FIG. 7, a fourth aspect of the present disclosure provides a method 700 performed by a fifth node for managing resources for a communication network. The method 700 comprises: a step S702, receiving, from a first node or third node, a fifth request for allocating infrastructure resources for an infrastructure cluster, the fifth request including a first parameter, or isolation requirements for the communication resources indicated by the first parameter; and a step S704, transmitting, to the first node or the third node, a fifth response indicating infrastructure resources for the infrastructure cluster satisfying the isolation requirements for the communication resources.
[0201] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirements; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0202] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / or an isolation requirement on a namespace or not.
[0203] In exemplary embodiments of the present disclosure, the third node comprises: a container infrastructure service cluster management, CCM; and the fifth node comprises at least one of: a management and orchestration, MANO, a cloud manager, or a cloud service producer.
[0204] FIG. 8A is a flow chart showing a method performed by a fifth node, according to exemplary embodiments of the present disclosure.
[0205] As shown in FIG. 8A, a fifth aspect of the present disclosure provides a method 800 performed by a fifth node for managing resources for a communication network. The method 800 comprises: a step S802, receiving, from a first node, a fourth request for creating a network service, the fourth request including a first parameter indicating isolation requirements for infrastructure resources providing the network service; and a step S804, transmitting, to the first node, a fourth response indicating the network service and the infrastructure resources satisfying the isolation requirements.
[0206] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0207] MANO allocate infra resources (e.g., VM / work node) for communication resource (e.g., NSS, NF, collection of NFs) .
[0208] In exemplary embodiments of the present disclosure, the communication resources comprise a managed object instance, MOI, for a collection of network functions, NF. The virtual machine node is hardened or not; and / or the infrastructure cluster comprises a container infrastructure service, CIS, cluster.
[0209] In exemplary embodiments of the present disclosure, the first parameter includes a value to indicate a strictness of the isolation requirement; and the first request further includes a second parameter indicating a deviation of the value of the first parameter.
[0210] FIG. 8B is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0211] As shown in FIG. 8B, in exemplary embodiments of the present disclosure, the method 800 further comprises: a step 806, transmitting, to a third node, a second request for an infrastructure cluster, the second request includes at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter; and a step 808, receiving, from the third node, a second response including an identifier of the CIS cluster satisfying the isolation requirement on the infrastructure cluster.
[0212] In exemplary embodiments of the present disclosure, the second request is for creating a new CIS cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster.
[0213] In exemplary embodiments of the present disclosure, the third node comprises: a container infrastructure service cluster management, CCM.
[0214] FIG. 8C is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0215] As shown in FIG. 8C, in exemplary embodiments of the present disclosure, the method 800 further comprises: a step S810, selecting an existing infrastructure cluster, when the existing infrastructure cluster satisfies an isolation requirement on the infrastructure cluster indicated by the first parameter, or by the first parameter and the second parameter.
[0216] FIG. 8D is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0217] As shown in FIG. 8D, in exemplary embodiments of the present disclosure, the method 800 further comprises: a step S812, transmitting, to a fourth node, a third request to deploy workloads over the communication resources, the third request including at least one of: the first parameter, the first parameter and the second parameter, and / or the isolation requirements for the communication resources indicated by the first parameter or by the first parameter and the second parameter; and a step S814, receiving, from the fourth node, a third response including addresses for the workloads.
[0218] In exemplary embodiments of the present disclosure, the third request further comprises: network security policies, and / or an identifier of a namespace.
[0219] In exemplary embodiments of the present disclosure, the fourth node comprises: a container infrastructure service management, CISM.
[0220] In exemplary embodiments of the present disclosure, the first node comprises: a Network Slice Subnet Management Service Producer, NSSMS_P; and the fifth node comprises: a management and orchestration, MANO.
[0221] According to embodiments of the present disclosure, the exemplary embodiments of the present disclosure propose a mechanism that allows to exchange isolation and security requirements of communication resources (such as network slice subnet / network functions, NSS / NF (s) ) between 5G / 6G (5th generation / 6th generation) network and cloud-native infrastructure in standard way, hence fulfill security and isolation requirements of 5G / 6G network in virtualization infrastructure, even in multi-vendor and multi cloud service provider scenarios.
[0222] The current disclosure mainly introduces a solution to unequivocally describe the isolation requirements for a communication resources, such as collection of cloud-native NFs / network slice subnet. It would be used during the allocation of a new virtualization resource to support network slice or NSS.
[0223] For example, the solutions introduce two new attributes:
[0224] ● Isolation Group Requirements (IGR) : a numerical value that is mapped to infrastructural requirements.
[0225] ● Isolation Level Deviation (ILD) : a numerical value that represent the maximum deviation between the required infrastructure and the used one.
[0226] Based on different deployment scenarios, the attributes should be supported by network slice subnet management service producer (NSSMS_P) (e.g., in case MNO manage the CIS cluster / K8S cluster) and / or cloud management and orchestration system (e.g., MANO) to support virtualization resource isolation. The attributes should be unambiguously interpreted by NSSMS_P / MANO and translated to correspondence isolation / security profiles / policies for virtualization resource deployment and configuration.
[0227] The solution will ensure that applications / network slices with the same isolation properties will obtain the same infrastructure with proper isolation, even when a mobile network operator (MNO, acting as network slice provider) integrates NFs from multiple vendors for its 5G / 6G network, and / or when the MNO communicates with different cloud service providers (CSPs) for virtualization resources to support its 5G / 6G network.
[0228] Further detailed embodiments will be illustrated below.
[0229] As to embodiment 1, detail exemplary definition of IGR and ILD will be illustrated.
[0230] Isolation Group Requirements (IGR) : it represents the isolation level required by a collection of NFs / NSS. It is a numeric value that spans from 1 to 100, where one represents no isolation and 100 represent the maximum available isolation. The value will be mapped to a set of isolation requirements that span from the hardware layer up to application layer. These requirements will be used both when deploying new collection of NFs / NSS or update already existing collection of NFs / NSS. The following table present a possible mapping for a cloud native deployment. In this case, the value is mapped with three different requirements of the virtualization stack. The first regards the isolation of the underlying machines, i.e., nodes, composing the Cluster. Secondly it analyzes the isolation requirements at the cluster / orchestrator level, i.e., dedicated / shared the cluster / control plane, and lastly it considers the isolation inside a cluster, e.g., networking isolation, which is mapped with a hardened namespace split.
[0231] The split is based on different threat vector of cloud native deployments and its increase in complexity. The least one aims to protect from an attacker that takes control of an application running inside the cluster. E. g., network isolation prevents an attacker to perform lateral movements and contact NFs belonging to a different NSS. Secondly, there is cluster isolation. This will prevent an attacker from taking control of the whole deployment of an NSS. E. g., if an attacker is able to exploit a vulnerability in the cluster and take control of the control plane, he will be able to control the deployment of the NFs belonging to a certain NSS and modify their configurations. Finally, continuing in the same direction, an attacker who is able to escape the container isolation and take control of the host machine, might affect the runtime of other VMs (Virtual Machine) running on the same hardware, even when those VMs belong to different clusters. HW (Hardware) split or hardened VM isolation is brought to prevent this kind of advance attack.
[0232] Table1 example IGR values and their mapping
[0233] *Namespaces could be intended as network isolated environment, e.g., it should be hardened with Network Policies, to prevent communications between NFs belonging to different NSS.
[0234] **This might be achieved through confidential Computing or other runtime isolation methods.
[0235] In the previous example, an exemplary top value, 100, is matched with the strictest constraints. In this case the application, i.e., all the NFs that belong to the NSS, will be deployed in dedicated namespaces in a dedicate Cluster. The node composing the clusters are dedicated machines, i.e., dedicated HW physically isolated from other machines.
[0236] Isolation Level Deviation (ILD) : it represents the maximum possible deviation from the required IGR. The value can be expressed both as a percentage or a fixed value. For example, if there is an IGR value of 80 and an ILD value of 10, the accepted range of IGR value will go from 70 to 90.
[0237] The isolation related parameters, for example, NetworkSliceSubnet->IsolationGroup. IsolationProfile, such as this defined in PCT / CN2023 / 112984, will be extended to support standardized isolation requirement in infrastructure level.
[0238] - isolation rule (e.g. dedicated / isolated, shared) ,
[0239] - security criteria (e.g. high level criteria such as SOC 2 Certified / EAL 3, or a list of security features, e.g. role based access control (RBAC) , Trusted Platform Module (TPM) , firewall (FW) , Web Application Firewall (WAF) , etc. )
[0240] As to an embodiment 2, a generic workflow of handling isolation level will be illustrated.
[0241] FIG. 9 is an exemplary diagram showing a generic workflow to handle the isolation parameter.
[0242] In a general deployment scenario, the various isolation requirements will be evaluated by one or multiple actors / entities of the deployment process. Indeed, the management system responsible for selecting the machines that will compose the cluster might not be the same as the one configuring the workload. For example, if considering the deployment mode showed in FIG. 1, the CCM would be interested only in the isolation requirements at HW level and cluster level but will not keep in consideration the isolation requirements proper of the workload. On the other hand, the CISM would need to evaluate the Namespace column, to configure the workload and deploy it to the workers node. On the same idea, the process might leverage the Isolation Level Deviation at different steps. For example, it might use it either when selecting a shared clusters or to adapt the requirements with the offering of the cloud provider.
[0243] The workflow in FIG. 9 depicts a generic process to map IGR and ILD to correspondence virtualization resource requirements and trigger related procedures to deploy and configure the resources for a NSS or collection of NFs.
[0244] The exemplary procedure may include following main steps in FIG. 9.
[0245] 1. An exemplary management function receives new resource request. After receiving a resource request for a NSS or a collection of NFs, the management function (MF) (e.g., NSSMS_P, MANO, NFVO, etc. ) retrieves IGR and ILD from the request.
[0246] 2. The MF converts the IGR into infrastructure resource requirement on the available cloud infrastructure.
[0247] 3. The MF determines whether a new cluster is required.
[0248] If new cloud native cluster is required according to infrastructure resource requirement mapped from the IGR, the MF goes to step 6.
[0249] Otherwise, the MF goes to step 4.
[0250] 4. The MF evaluates accepted ranges based on IGR ± ILD, and look for available cluster with properties inside the range. The MF goes to step 5.
[0251] 5. The MF determines whether there is a match.
[0252] If there is a match, the MF goes to step 7.
[0253] Otherwise, the MF goes to step 6.
[0254] 6. The MF triggers to deploy and configure infrastructure resources (e.g., physical or virtual machine accordingly) as work node (s) for the cluster, then setup the cluster with the work node (s) . Then, the MF goes to step 8.
[0255] 7. If a matched cluster is found, the MF may trigger to update the cluster (optionally) .
[0256] 8. After steps 3-7, the MF triggers to deploy and configure workload for the NSS / collection of NFs.
[0257] Based on business and deployment model, the entity / actor executes the above workflow could be network slice management service producer (NSSMS_P) , Management and Orchestration (MANO) (e.g., Network Function Orchestration (NFVO) ) , cloud infrastructure service cluster management (e.g., CCM) , cloud infrastructure service management (e.g., CISM) , etc.
[0258] Further, following Notes related to some steps may be further illustrated.
[0259] Note 1. Resource could be NSS, collection of NFs, network service, collection of VNFs / CNFs or single CNF / VNF, cloud infrastructure service cluster, collection of PoDs / single PoD, etc.
[0260] Note 2. The MF entity may call other entities to deploy infrastructure, and setup cluster.
[0261] Note 3. The existing cluster may be updated (e.g., scaling out) to support new resource Note requirement.
[0262] Note 4. The MF entity may call other entity to deploy and configure the workload in the cluster node (s) .
[0263] An exemplary embodiment 3 illustrates resource isolation in an option 1 of network slice subnet deployment.
[0264] FIG. 10A is a diagram showing an exemplary signal flow of deployment option 1.
[0265] The exemplary procedure may include following main steps in FIG. 10A.
[0266] 1. NSSMS producer (NSSMS_P) received request from NSSMS consumer (NSSMS_C) to create NSS managed object instance (MOI) , which includes IGR and ILD together with other parameters, such as security criteria in isolation profile.
[0267] 2. NSSMS_P maps IGR (and ILD) to corresponding CIS requirements.
[0268] 3. If dedicated cluster is required according to IGR value, NSSMS_P requests new cluster from CCM. IGR and / or ILD, or equivalent attributes mapped from IGR and ILD, will be sent to CCM. Alternatively, NSSMS_P may request a cluster from CCM, and CCM may decide whether to create a new cluster or allocate an existing cluster based on IGR and / or ILD.
[0269] 4. CCM maps IGR and ILD, or the equivalent, to virtualization infrastructure requirements, and calls NFV MANO to allocate virtualization resources / infrastructures. The IGR and / or ILD, or equivalent attributes mapped from IGR and / or ILD, will be sent to the MANO. The request will trigger MANO to allocate dedicated hardware or deploy VMs based on IGR and / or ILD, or the equivalent, the VMs may be hardened according to IGR and ILD.
[0270] 5. The CCM receives a response from the MANO. After received response from MANO, CCM takes the allocated resources as CIS nodes, and setup CIS cluster with the nodes.
[0271] 6. CCM sends response to NSSMS_P with cluster ID, and address of CISM, which represents control plane of the cluster.
[0272] As alternative of step 3-6, NSSMS_P may select an existing cluster for the NSS MOI based on IGR and / or ILD.
[0273] 7. NSSMF_P calls CISM to deploy workload for the constituent NFs of the NSS MOI. IGR and / or ILD, or equivalent attributes mapped from IGR and / or ILD, will be sent to the CISM. In addition, the application configuration to isolate the namespace, such as network policies, for inter / intra NSS isolation may be included in the request.
[0274] 8. CISM assigns and configure the resources for the workload, and configure network policies to prevent communication between NFs, especially of different NSSs.
[0275] 9. CISM sends response to NSSMS_P with address of workloads, and namespace id.
[0276] 10. NSSMS_P performs post-commission configurations for the NFs.
[0277] 11. NSSMS_P sends response to NSSMS_C with NSS MOI Id.
[0278] An exemplary embodiment 4 illustrates resource isolation in an option 2 of network slice subnet deployment.
[0279] FIG. 10B is a diagram showing some adjustments for the FIG. 10B.
[0280] In the FIG. 10B, compared to FIG. 10A, the CCM may be omitted. Accordingly, the NSSMS_P may link the infrastructure nodes together for a cluster, instead performing a step 3 to request the CCM to assign a cluster. Further, in an alternative step 4, the NSSMS_P may call NFV MANO to allocate virtualization resources / infrastructures. In an alternative step 5, the NSSMS_P receives a response from the MANO. After received response from MANO, and setup CIS cluster configuration.
[0281] That is, in FIG. 10B, alternatively, the NSSMS_P may request a MANO / cloud manager / cloud service producer for infrastructure resource (e.g. machines or VMs) , then create a infrastructure cluster, e.g. K8s cluster, by configuring the control plane and linking the machines / VMs together.
[0282] FIG. 11 is a diagram showing an exemplary signal flow of deployment option 2.
[0283] The cloud service provider (CSP) takes full control on the container infrastructure service, MANO is an access point provided to cloud service consumer (CSC) , such as MNO. In this scenario, NSSMS_P passes IGR and / or ILD, or the equivalent attributes, to access point of the CSP for CIS, then the management functions in CSP will determine and deploy resources for the NSS MOI based on IGR and / or ILD, or the equivalent.
[0284] The exemplary procedure may include following main steps in FIG. 11.
[0285] 1. NSSMS producer (NSSMS_P) received request from NSSMS consumer (NSSMS_C) to create NSS managed object instance (MOI) , which includes IGR and ILD together with other parameters, such as security criteria in isolation profile.
[0286] 2. NSSMS_P requires the MANO to create NS. The request may include IGR (and ILD) to corresponding CIS requirements.
[0287] 3. If dedicated cluster is required according to IGR value, MANO requests new cluster from CCM. IGR and / or ILD, or equivalent attributes mapped from IGR and ILD, will be sent to CCM. Alternatively, MANO may request a cluster from CCM, and CCM may decide whether to create a new cluster or allocate an existing cluster based on IGR and / or ILD.
[0288] 4. The CCM communicates to CISM to set up cluster configuration.
[0289] 5. CCM sends response to MANO with cluster ID, and address of CISM, which represents control plane of the cluster. As alternative of step 3-5, MANO may select an existing cluster for the NSS MOI based on IGR and / or ILD.
[0290] 6. MANO calls CISM to deploy workload for the constituent NFs of the NSS MOI. IGR and / or ILD, or equivalent attributes mapped from IGR and / or ILD, will be sent to the CISM. In addition, the application configuration to harden the namespace, such as network policies, for inter / intra NSS isolation may be included in the request.
[0291] 7. CISM assigns and configure the resources for the workload, and configure network policies to prevent communication between NFs, especially of different NSSs.
[0292] 8. CISM sends response to MANO with address of workloads, such as MCIO, and namespace id.
[0293] 9. MANO sends response to NSSMS_P for the NS, including the allocated VNFs, etc.
[0294] 10. NSSMS_P sends response to NSSMS_C with NSS MOI Id.
[0295] 11. NSSMS_P performs post-commission configurations for the NFs.
[0296] The exemplary embodiments of the present disclosure may provide many implementations and advantages.
[0297] For example, in 3GPP, an unequivocally value may be defined to represent levels the isolation requirements for a collection of cloud-native NFs / network slice subnet.
[0298] The interfaces / formulate requirements on virtualization resource isolation and security for 5G / 6G network based on various cloud technologies may be abstracted, therefore enabling integration of 5G / 6G network to different cloud providers.
[0299] Isolation / security requirements in standardized profile / descriptor for specific group of NFs may be defined based on capabilities provided by cloud providers. The capabilities may be reflected in specification defined by another Service Data Objects (SDO) (e.g. ETSI NFV) or de-facto standardization developed in open source (e.g. K8S) or other projects (such as CSA, National Institute of Standards and Technology (NIST ) , etc. ) , hence enable integration of multi-vendors’ NFs (e.g. different type of NFs may be provided by different vendors or NFs of different slices / NSSs are provided by different vendors) in cloud-native 5G / 6G network.
[0300] FIG. 12 is a block diagram showing an exemplary structure for a first node, according to exemplary embodiments of the present disclosure.
[0301] As shown in FIG. 12, the first node 120 comprises means 1200 configured for: receiving, from a second node, a first request for communication resources, the first request including: a first parameter indicating isolation requirements for the communication resources; and transmitting, to the second node, a first response indicating the communication resources satisfying the isolation requirements for the communication resources.
[0302] In exemplary embodiments of the present disclosure, the isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0303] In exemplary embodiments of the present disclosure, the means 1200 are further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 4A, 4B, 4C, 4D, 4E, FIG. 9, FIG. 10A, FIG. 10B, FIG. 11.
[0304] In exemplary embodiments of the present disclosure, the means 1200 comprise: at least one processor 1202; and at least one memory 1204 storing instructions that, when executed by the at least one processor 1202, cause the performance of the first node 120.
[0305] Correspondingly, a second node may comprise means configured for: transmitting, to the first node, a first request for communication resources, the first request including: a first parameter indicating isolation requirements for the communication resources; and receiving, from the first node, a first response indicating the communication resources satisfying the isolation requirements for the communication resources. The means may comprise: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the performance of the second node.
[0306] The isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0307] FIG. 13 is a block diagram showing an exemplary structure for a third node, according to exemplary embodiments of the present disclosure.
[0308] As shown in FIG. 13, the third node 130 comprises means 1300 configured for: receiving, from a first node or a fifth node, a second request for an infrastructure cluster, the second request including a first parameter, or an isolation requirement on the infrastructure cluster indicated by the first parameter; and transmitting, to the first node or the fifth node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.
[0309] In exemplary embodiments of the present disclosure, the means 1300 are further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 5A, 5B, 9, 10, 11.
[0310] In exemplary embodiments of the present disclosure, the means 1300 comprise: at least one processor 1302; and at least one memory 1304 storing instructions that, when executed by the at least one processor 1302, cause the performance of the third node 130.
[0311] FIG. 14 is a block diagram showing an exemplary structure for a fourth node, according to exemplary embodiments of the present disclosure.
[0312] As shown in FIG. 14, the fourth node 140 comprises means 1400 configured for: receiving, from a first node or a fifth node, a third request to deploy workloads for communication resources, the third request including: isolation requirements for the communication resources, and / or a first parameter indicating the isolation requirements for the communication resources; and transmitting, to the first node or the fifth node, a third response including addresses for the workloads.
[0313] In exemplary embodiments of the present disclosure, the means 1400 are further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 6, 9, 10, 11.
[0314] In exemplary embodiments of the present disclosure, the means 1400 comprise: at least one processor 1402; and at least one memory 1404 storing instructions that, when executed by the at least one processor 1402, cause the performance of the fourth node 140.
[0315] FIG. 15 is a block diagram showing an exemplary structure for a fifth node, according to exemplary embodiments of the present disclosure.
[0316] As shown in FIG. 15, the fifth node 150 comprises means 1500 configured for: receiving, from first node or a third node, a fifth request for allocating infrastructure resources for an infrastructure cluster, the fifth request including a first parameter, or isolation requirements for the communication resources indicated by the first parameter; and transmitting, to the first node or the third node, a fifth response indicating infrastructure resources for the infrastructure cluster satisfying the isolation requirements for the communication resources.
[0317] In exemplary embodiments of the present disclosure, the means 1500 are further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 7, 9, 10, 11.
[0318] Alternatively, the means 1500 may be configured for: receiving, from a first node, a fourth request for creating a network service, the fourth request including a first parameter indicating isolation requirements for infrastructure resources providing the network service; and transmitting, to the first node, a fourth response indicating the network service and the infrastructure resources satisfying the isolation requirements.
[0319] The isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0320] In exemplary embodiments of the present disclosure, the means 1500 are further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 8A, 8B, 8C, 8D, 9, 10, 11.
[0321] In exemplary embodiments of the present disclosure, the means 1500 comprise: at least one processor 1502; and at least one memory 1504 storing instructions that, when executed by the at least one processor 1502, cause the performance of the fifth node 150.
[0322] The processor 1202, 1302, 1402, 1502 may be any kind of processing component, such as one or more microprocessor or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs) , special-purpose digital logic, and the like. The memory 1204, 1304, 1404, 1504 may be any kind of storage component, such as read-only memory (ROM) , random-access memory, cache memory, flash memory devices, optical storage devices, etc.
[0323] FIG. 16 is a block diagram showing an apparatus / computer readable storage medium, according to embodiments of the present disclosure.
[0324] As shown in FIG. 16, a computer-readable storage medium 160 storing instructions 161, which when executed by at least one processor of a node (such as the first, second, third, fourth, fifth node) , cause the at least one processor of the node to perform the method according to any of the embodiments above mentioned, such as shown in FIG. 4A, 4B, 4C, 4D, 4E, 5A, 5B, 6, 7, 8A, 8B, 8C, 8D, 9, 10, 11.
[0325] In addition, the present disclosure may also provide a carrier containing the computer program / instructions as mentioned above. The carrier is one of an electronic signal, optical signal, radio signal, or the above computer readable storage medium. The computer readable storage medium can be, for example, an optical compact disk or an electronic memory device like a RAM (random access memory) , a ROM (read only memory) , Flash memory, magnetic tape, CD-ROM, DVD, Blue-ray disc and the like.
[0326] FIG. 17 is a block diagram showing exemplary apparatus units for a first node, which is suitable for performing the method according to embodiments of the disclosure.
[0327] As shown in FIG. 17, the first node 170 may include: a receiving unit 1702, configured for: receiving, from a second node, a first request for communication resources, the first request including: a first parameter indicating isolation requirements for the communication resources; and a transmitting unit 1704, configured for transmitting, to the second node, a first response indicating the communication resources satisfying the isolation requirements for the communication resources.
[0328] The isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0329] In exemplary embodiments of the present disclosure, the first node 170 is further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 4A, 4B, 4C, 4D, 4E, FIG. 9, FIG. 10 A, FIG. 10B, FIG. 11.
[0330] FIG. 18 is a block diagram showing exemplary apparatus units for a third node, which is suitable for performing the method according to embodiments of the disclosure.
[0331] As shown in FIG. 18, the third node 180 may include: a receiving unit 1802, configured for receiving, from a first node or a fifth node, a second request for an infrastructure cluster, the second request including a first parameter, or an isolation requirement on the infrastructure cluster indicated by the first parameter; and a transmitting unit 1804, configured for transmitting, to the first node or the fifth node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.
[0332] In exemplary embodiments of the present disclosure, the third node 200 is further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 5A, 5B, 9, 10, 11.
[0333] FIG. 19 is a block diagram showing exemplary apparatus units for a fourth node, which is suitable for performing the method according to embodiments of the disclosure.
[0334] As shown in FIG. 19, the fourth node 190 may include: a receiving unit 1902, configured for receiving, from a first node or a fifth node, a third request to deploy workloads for communication resources, the third request including: isolation requirements for the communication resources, and / or a first parameter indicating the isolation requirements for the communication resources; and a transmitting unit 1904, configured for transmitting, to the first node or the fifth node, a third response including addresses for the workloads.
[0335] In exemplary embodiments of the present disclosure, the fourth node 210 is further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 6, 9, 10, 11.
[0336] FIG. 20 is a block diagram showing exemplary apparatus units for a fifth node, which is suitable for performing the method according to embodiments of the disclosure.
[0337] As shown in FIG. 20, the fifth node 200 may include: a receiving unit 2002, configured for receiving, from a first node or a third node, a fifth request for allocating infrastructure resources for an infrastructure cluster, the fifth request including a first parameter, or isolation requirements for the communication resources indicated by the first parameter; and a transmitting unit 2004, configured for transmitting, to the first node or the third node, a fifth response indicating infrastructure resources for the infrastructure cluster satisfying the isolation requirements for the communication resources.
[0338] In exemplary embodiments of the present disclosure, the fourth node 210 is further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 7, 9, 10, 11.
[0339] Alternatively, the receiving unit 2002 may be configured for receiving, from a first node, a fourth request for creating a network service, the fourth request including a first parameter indicating isolation requirements for infrastructure resources providing the network service; and the transmitting unit 2004 may be configured for transmitting, to the first node, a fourth response indicating the network service and the infrastructure resources satisfying the isolation requirements.
[0340] The isolation requirements for the communication resources include at least one of: an isolation requirement on a hardware node or a virtual machine node; an isolation requirement on an infrastructure cluster being dedicated or being shared; and / or an isolation requirement on a namespace or not.
[0341] In exemplary embodiments of the present disclosure, the fourth node 210 is further configured for performing the method according any of the embodiments above mentioned, such as shown in FIG. 8A, 8B, 8C, 8D, 9, 10, 11.
[0342] The term ‘unit’ may have conventional meaning in the field of electronics, electrical devices and / or electronic devices and may include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein.
[0343] As used in the present disclosure, the term “circuitry” may refer to one or more or all of the following:
[0344] (a) hardware-only circuit implementations (such as implementations in only analogy and / or digital circuitry) and
[0345] (b) combinations of hardware circuits and software, such as (as applicable) :
[0346] (i) a combination of analogy and / or digital hardware circuit (s) with software / firmware and
[0347] (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
[0348] (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. ”
[0349] This definition of circuitry applies to all uses of this term in the present disclosure, including in any claims. As a further example, as used in the present disclosure, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0350] With these units, the apparatus may not need a fixed processor or memory, any kind of computing resource and storage resource may be arranged from at least one node / device / entity / apparatus relating to the communication system. The virtualization technology and network computing technology (e.g., cloud computing) may be further introduced, so as to improve the usage efficiency of the network resources and the flexibility of the network.
[0351] The techniques described herein may be implemented by various means so that an apparatus implementing one or more functions of a corresponding apparatus described with an embodiment comprises not only prior art means, but also means for implementing the one or more functions of the corresponding apparatus described with the embodiment and it may comprise separate means for each separate function, or means that may be configured to perform two or more functions. For example, these techniques may be implemented in hardware (one or more apparatuses) , firmware (one or more apparatuses) , software (one or more modules / units) , or combinations thereof. For a firmware or software, implementation may be made through modules (e.g., procedures, functions, and so on) that perform the functions described herein.
[0352] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionalities may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.
[0353] The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .
[0354] As described in above exemplary embodiments of this disclosure, embodiments herein afford many advantages. According to embodiments of the present disclosure, the exemplary embodiments of the present disclosure propose a mechanism that allows to exchange isolation and security requirements of communication resources (such as network slice subnet / network functions, NSS / NF (s) ) between 5G / 6G (5th generation / 6th generation) network and cloud-native infrastructure in standard way, hence fulfill security and isolation requirements of 5G / 6G network in virtualization infrastructure, even in multi-vendor and multi cloud service provider scenarios.
[0355] It should be understood that the above embodiments are only for illustration but not limitation. The present disclosure may be carried out in other ways than those specifically set forth herein without departing from essential characteristics of the disclosure. All changes to these embodiments not departing from the meaning and equivalency of the appended claims are intended to be comprised herein.
[0356] REFERENCES
[0357] The followings are the references which are incorporated herein in their entirety:
[0358] PCT / CN2023 / 112984;
[0359] ETSI GR NFV-IFA 029 V3.3.1 (2019-11) , Network Functions Virtualisation (NFV) Release 3; Architecture; Report on the Enhancements of the NFV architecture towards "Cloud-native" and "PaaS" ;
[0360] ETSI GS NFV-IFA 036 V4.5.1 (2023-09) , Network Functions Virtualisation (NFV) Release 4; Management and Orchestration; Requirements for service interfaces and object model for container cluster management and orchestration specification;
[0361] ETSI GR NFV-IFA 043 V0.1.0 (2023-06) , Network Functions Virtualisation (NFV) Release 5; Architectural Framework; Report on enhanced container networking; "work in progress" ;
[0362] ETSI GS NFV-SEC 023 V0.0.6 (2022-09) ) , Network Functions Virtualisation (NFV) ; Security; Container Security Specification Release 4; "work in progress" ;
[0363] 3GPP TR (technical report) 33.848 (V18.0.0 (2023-09) )
[0364] ABBREVIATION EXPLANATION CNF Containerized Network Function MnS Management Service MOI Managed Object Instance NFMS_P Network Function Management Service Producer NSMS_P Network Slice Management Service Producer NSSMS_P Network Slice Subnet Management Service Producer NRM Network Resource Model NSC Network Service Customer NSP Network Service Provider NS Network Service NSS Network Slice Subnet VNF Virtual Network Function S-NSSAI Single Network Slice Selection Assistance Information NSI Network Slice Instance
Claims
A method (400) performed by a first node for managing resources for a communication network, comprising:receiving (S402) , from a second node, a first request for communication resources, the first request including: a first parameter indicating isolation requirements for the communication resources; andtransmitting (S404) , to the second node, a first response indicating the communication resources satisfying the isolation requirements for the communication resources.The method (400) according to claim 1,wherein the isolation requirements for the communication resources include at least one of:an isolation requirement on a hardware node or a virtual machine node;an isolation requirement on an infrastructure cluster being dedicated or being shared; and / oran isolation requirement on a namespace or not.The method (400) according to claim 1 or 2,wherein the communication resources comprise a managed object instance, MOI, for a collection of network functions, NF; and / orwherein the virtual machine node is hardened or not; and / orwherein the infrastructure cluster comprises a container orchestrator cluster.The method according to any of claims 1 to 3,wherein the first parameter includes a value to indicate a strictness of the isolation requirements; andwherein the first request further includes a second parameter indicating a deviation of the value of the first parameter.The method (400) according to claim 4, further comprising:transmitting (S406) , to a third node, a second request for an infrastructure cluster, wherein the second request includes at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter; andreceiving (S408) , from the third node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.The method (400) according to claim 5,wherein the second request is for creating a new infrastructure cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster.The method (400) according to claim 5 or 6, wherein the third node comprises at least one of: a container infrastructure service cluster management, CCM, a management and orchestration, MANO, a cloud manager, or a cloud service producer.The method (400) according to claim 4, further comprising:selecting (S410) an existing infrastructure cluster, when the existing infrastructure cluster satisfies an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter.The method (400) according to any of claims 4 to 8, further comprising:transmitting (S412) , to a fourth node, a third request to deploy workloads for the communication resources, the third request including at least one of: the first parameter, the first parameter and the second parameter, and / or the isolation requirements for the communication resources indicated by the first parameter or by the first parameter and the second parameter; andreceiving (S414) , from the fourth node, a third response including addresses for the workloads.The method (400) according to claim 9,wherein the third request further comprises: network security policies, and / or an identifier of a namespace.The method (400) according to claim 9 or 10,wherein the fourth node comprises at least one of: a container infrastructure service management, CISM, a K8s control plane or a k8s apiserver.The method (400) according to claim 4, further comprising:transmitting (S416) , to a fifth node, a fourth request for creating a network service, the fourth request including at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the network service indicated by the first parameter or by the first parameter and the second parameter; andreceiving (S418) , from the fifth node, a fourth response indicating the network service satisfying the isolation requirement on the network service and infrastructure resources for communication resources.The method (400) according to claim 4, further comprising:transmitting (S406’) , to a fifth node, a fifth request for allocating infrastructure nodes for a cluster; andlinking (S407’) infrastructure nodes together for a cluster.The method (400) according to claim 12 or 13,wherein the fifth node comprises at least one of: a management and orchestration, MANO, a cloud manager, or a cloud service producer.The method (400) according to any of claims 1 to 14,wherein the first node comprises: a Network Slice Subnet Management Service Producer, NSSMS_P; andwherein the second node comprises: a Network Slice Subnet Management Service Consumer, NSSMS_C.A method (500) performed by a third node for managing resources for a communication network, comprising:receiving (S502) , from a first node or a fifth node, a second request for an infrastructure cluster, the second request including a first parameter, or an isolation requirement on the infrastructure cluster indicated by the first parameter; andtransmitting (S504) , to the first node or the fifth node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.The method (500) according to claim 16,wherein the first parameter further indicates:an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / oran isolation requirement on a namespace or not.The method (500) according to claim 16 or 17,wherein the first parameter includes a value to indicate a strictness of the isolation requirement on the infrastructure cluster; andwherein the first request further includes a second parameter indicating a deviation of the value of the first parameter.The method (500) according to claim 18,wherein the third node creates a new infrastructure cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster; orwherein the third node assigns an existing infrastructure cluster.The method (500) according to any of claims 16 to 19, further comprising:transmitting (S506) , to the fifth node, a fifth request for allocating infrastructure resources for the infrastructure cluster, the fifth request including the first parameter, or an isolation requirement on the infrastructure resource s indicated by the first parameter; andreceiving (S508) , from the fifth node, a fifth response indicating the infrastructure resources s for the infrastructure cluster satisfying the isolation requirement on the infrastructure resources.The method (500) according to any of claims 16 to 20,wherein the fifth node comprises: a MANO, a cloud manager, or a cloud service producer.The method (500) according to any of claims 16 to 21,wherein the first node comprises: a NSSMS_P; andwherein the third node comprises at least one of: a CCM, a MANO, a cloud manager, or a cloud service producer.A method (600) performed by a fourth node for managing resources for a communication network, comprising:receiving (S602) , from a first node or a fifth node, a third request to deploy workloads for communication resources, the third request including: isolation requirements for the communication resources, and / or a first parameter indicating the isolation requirements for the communication resources; andtransmitting (S604) , to the first node or the fifth node, a third response including addresses for the workloads.The method (600) according to claim 23,wherein the isolation requirements for the communication resources include at least one of:an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / oran isolation requirement on a namespace or not.The method (600) according to claim 23 or 24,wherein the first parameter includes a value to indicate a strictness of the isolation requirements; andwherein the first request further includes a second parameter indicating a deviation of the value of the first parameter.The method (600) according to any of claims 23 to 25,wherein the third request further comprises: network security policies, and / or an identifier of a namespace.The method (600) according to any of claims 23 to 26,wherein the first node comprises: a NSSMS_P;wherein the fourth node comprises at least one of: a CISM, a K8s control plane or a k8s apiserver; andwherein the fifth node comprises at least one of: a MANO, a cloud manager, or a cloud service producer.A method (700) performed by a fifth node for managing resources for a communication network, comprising:receiving (S702) , from a first node or a third node, a fifth request for allocating infrastructure resources for an infrastructure cluster, the fifth request including a first parameter, or isolation requirements for the communication resources indicated by the first parameter; andtransmitting (S704) , to the first node or the third node, a fifth response indicating infrastructure resources for the infrastructure cluster satisfying the isolation requirements for the communication resources.The method (700) according to claim 28,wherein the first parameter includes a value to indicate a strictness of the isolation requirements; andwherein the first request further includes a second parameter indicating a deviation of the value of the first parameter.The method (700) according to claim 29,wherein the isolation requirements for the communication resources include at least one of:an isolation requirement on a hardware node or a virtual machine node, the virtual machine node being hardened or not; and / oran isolation requirement on a namespace or not.The method (700) according to any of claims 28 to 30wherein the third node comprises: a CCM; andwherein the fifth node comprises at least one of: a MANO, a cloud manager, or a cloud service producer.A method (800) performed by a fifth node for managing resources for a communication network, comprising:receiving (S802) , from a first node, a fourth request for creating a network service, the fourth request including a first parameter indicating isolation requirements on infrastructure resources providing the network service; andtransmitting (S804) , to the first node, a fourth response indicating the network service and the infrastructure resources satisfying the isolation requirements.The method (800) according to claim 32,wherein the isolation requirements for the communication resources include at least one of:an isolation requirement on a hardware node or a virtual machine node;an isolation requirement on an infrastructure cluster being dedicated or being shared; and / oran isolation requirement on a namespace or not.The method (800) according to claim 32,wherein the communication resources comprise a managed object instance, MOI, for a collection of network functions, NF;wherein the virtual machine node is hardened or not; and / orwherein the infrastructure cluster comprises a container infrastructure service, CIS, cluster.The method (800) according to any of claims 32 to 34,wherein the first parameter includes a value to indicate a strictness of the isolation requirement; andwherein the first request further includes a second parameter indicating a deviation of the value of the first parameter.The method (800) according to claim 35, further comprising:transmitting (S806) , to a third node, a second request for an infrastructure cluster, wherein the second request includes at least one of: the first parameter, the first parameter and the second parameter, and / or an isolation requirement on the infrastructure cluster indicated by the first parameter or by the first parameter and the second parameter; andreceiving (S808) , from the third node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster.The method (800) according to claim 36,wherein the second request is for creating a new infrastructure cluster, when a dedicated infrastructure cluster is required according to the first parameter, or according to the first parameter and the second parameter, or according to the isolation requirement on the infrastructure cluster.The method (800) according to claim 36 or 37, wherein the third node comprises: a container infrastructure service cluster management, CCM.The method (800) according to any of claims 36 to 38, further comprising:selecting (S810) an existing infrastructure cluster, when the existing infrastructure cluster satisfies an isolation requirement on the infrastructure cluster indicated by the first parameter, or by the first parameter and the second parameter.The method (800) according to any of claims 36 to 39, further comprising:transmitting (S812) , to a fourth node, a third request to deploy workloads over the communication resources, the third request including at least one of: the first parameter, the first parameter and the second parameter, and / or the isolation requirements for the communication resources indicated by the first parameter or by the first parameter and the second parameter; andreceiving (S814) , from the fourth node, a third response including addresses for the workloads.The method (800) according to claim 40,wherein the third request further comprises: network security policies, and / or an identifier of a namespace.The method (800) according to claim 40 or 41,wherein the fourth node comprises: a container infrastructure service management, CISM.The method (800) according to any of claims 32 to 42,wherein the first node comprises: a Network Slice Subnet Management Service Producer, NSSMS_P; andwherein the fifth node comprises: a management and orchestration, MANO, a cloud manager, or a cloud service producer.A first node (120) comprising means (1200) configured for:receiving, from a second node, a first request for communication resources, the first request including: a first parameter indicating isolation requirements for the communication resources; andtransmitting, to the second node, a first response indicating the communication resources satisfying the isolation requirements for the communication resources;wherein the means (1200) comprise:at least one processor (1202) ; andat least one memory (1204) storing instructions that, when executed by the at least one processor (1202) , cause the performance of the first node (120) .The first node (120) according to claim 44, wherein the means (1200) are further configured for performing the method according to any of the claims 2 to 15.A third node (130) comprising means (1300) configured for:receiving, from a first node or a fifth node, a second request for an infrastructure cluster, the second request including a first parameter, or an isolation requirement on the infrastructure cluster indicated by the first parameter; andtransmitting, to the first node or the fifth node, a second response including an identifier of the infrastructure cluster satisfying the isolation requirement on the infrastructure cluster;wherein the means (1300) comprise:at least one processor (1302) ; andat least one memory (1304) storing instructions that, when executed by the at least one processor (1302) , cause the performance of the third node (130) .The third node (130) according to claim 46, wherein the means (1300) are further configured for performing the method according to any of the claims 17 to 22.A fourth node (140) comprising means (1300) configured for:receiving, from a first node or a fifth node, a third request to deploy workloads for communication resources, the third request including: isolation requirements for the communication resources, and / or a first parameter indicating the isolation requirements for the communication resources; andtransmitting, to the first node or the fifth node, a third response including addresses for the workloads;wherein the means (1400) comprise:at least one processor (1402) ; andat least one memory (1404 storing instructions that, when executed by the at least one processor (1402) , cause the performance of the fourth node (140) .The fourth node (140) according to claim 48, wherein the means (1400) are further configured for performing the method according to any of the claims 24 to 27.A fifth node (150) comprising means (1500) configured for:receiving, from first node or a third node, a fifth request for allocating infrastructure resources for an infrastructure cluster, the fifth request including a first parameter, or isolation requirements for communication resources indicated by the first parameter; andtransmitting, to the first node or the third node, a fifth response indicating infrastructure resources for the infrastructure cluster satisfying the isolation requirements for the communication resources;wherein the means (1500) comprise:at least one processor (1502) ; andat least one memory (1504) storing instructions that, when executed by the at least one processor (1502) , cause the performance of the fifth node (150) .The fifth node (150) according to claim 50, wherein the means (1500) are further configured for performing the method according to any of the claims 29 to 31.A fifth node (150) comprising means (1500) configured for:receiving, from a first node, a fourth request for creating a network service, the fourth request including a first parameter indicating isolation requirements on infrastructure resources providing the network service; andtransmitting, to the first node, a fourth response indicating the network service and the infrastructure resources satisfying the isolation requirements;wherein the means (1500) comprise:at least one processor (1502) ; andat least one memory (1504) storing instructions that, when executed by the at least one processor (1502) , cause the performance of the fifth node (150) .The fifth node (150) according to claim 52, wherein the means (1500) are further configured for performing the method according to any of the claims 33 to 43.A computer-readable storage medium (160) storing instructions (161) , which when executed by at least one processor of a node, cause the at least one processor of a node to perform the method according to any of claims 1 to 43.