System for updating network slicing through dynamic resource allocation, and method for ensuring mobility of host

The network slicing update system with dynamic resource allocation addresses inefficiencies and handoff challenges by selectively updating network slices and reallocating resources, ensuring seamless connectivity and security in dynamic wireless environments.

WO2026105926A1PCT designated stage Publication Date: 2026-05-21TRENTO SYST INC
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
TRENTO SYST INC
Filing Date
2024-11-26
Publication Date
2026-05-21

Smart Images

  • Figure KR2024018869_21052026_PF_FP_ABST
    Figure KR2024018869_21052026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a system for updating network slicing through dynamic resource allocation, and a method for ensuring mobility of a host by using same. According to the present invention, a system for updating network slicing through dynamic resource allocation comprises: an update request receiving unit for receiving a network slicing update request; a removal target host identification and resource release unit for identifying a removal target host and releasing resources according to the update request; and an addition target host identification and resource allocation unit for identifying an addition target host and allocating resources. According to the present invention, a method for ensuring mobility of a host by using a system for updating network slicing through dynamic resource allocation comprises the steps of: (a) detecting movement of a host registered in a network slice; and (b) performing handoff using a data link layer without using an IP address in relation to the movement of the host.
Need to check novelty before this filing date? Find Prior Art

Description

Network slicing update system through dynamic resource allocation and method to guarantee host mobility

[0001] The present invention relates to a network slicing update system through dynamic resource allocation and a method for guaranteeing host mobility using the same.

[0002] According to the prior art disclosed in Korean Registered Patent Publication No. 10-1754618, a technology for creating virtual networks based on software-defined networks was proposed; however, there are problems such as wasted network resources and unnecessary bandwidth consumption during the management and removal of multiple links. Additionally, when changing network configurations, the tree generation process is complex, leading to performance degradation and inefficient use of network resources.

[0003] According to the prior art disclosed in Korean Published Patent Application No. 10-2020-0011079, the software update of a virtualized network device / system is described. This method maintains service continuity by creating a new device, switching traffic, and then removing the existing device during the software update. However, this method has issues related to performance degradation occurring during the update process. Additionally, there are issues related to delays or instability of traffic switching occurring at the time of traffic switching.

[0004] According to the prior art Korean Published Patent Application No. 10-2018-0122513, details regarding traffic engineering in a network hyperfinder of a software-defined network-based network virtualization platform are disclosed. However, this requires complex traffic engineering to ensure the communication quality of the virtual network, and there is a problem in that the mapping of physical paths cannot be rapidly updated in the event of a failure.

[0005] According to the prior art disclosed in Korean Published Patent Application No. 10-2017-0048913, network nodes are virtualized through network function virtualization, and network resources are utilized through the selection of virtualized network nodes. While this offers the advantage of providing flexibility by separating hardware and software, it has the problem of requiring complex management in multiple virtualization layers and various routing path settings. Furthermore, if the location information of a terminal changes frequently or the network status is unstable, routing changes between network nodes occur frequently, which places a burden on system performance.

[0006] Handoff in wireless networks is a hard handoff between access points (APs or Base Stations), and instantaneous data loss is inevitable. In particular, in a wireless LAN environment, user terminals are assigned IP addresses from APs or higher-level devices. Since packets are routed according to destination addresses at the IP layer, if communication needs to be maintained even when a terminal moves to a different subnet, the IP address must be changed to one with the network prefix of the corresponding network whenever the network is changed. In this case, since higher-layer connections such as TCP connections are not guaranteed, continuous communication becomes impossible.

[0007] Therefore, in order to maintain the existing address and continue to be in a state where communication is possible, a Layer 3 protocol called Mobile IP, which can guarantee continuity, must be used. However, since wireless LANs are designed without considering compensation for data loss, they cannot support real-time services as upper-level application services.

[0008] In the case of wireless LANs, efficient handoff cannot be provided if there is no handoff support at Layer 2, and as mentioned above, handoff in current wireless LANs supports Layer 3 handoff using Mobile IP. However, Mobile IP defines Layer 3 handoff (also called loading in wireless LANs) regardless of the technology for the lower Layer 2, and does not take into account matters regarding handoff that supports real-time handoff and inter-cell mobility.

[0009] Therefore, in wireless network environments where small cells and pico cells are increasing for high-speed services, and in island-type networks such as smart cities and autonomous driving, there is a need to design a handoff method at Layer 2 (Data Link Layer) based on a dynamic network slicing update system that can solve problems caused by IP changes while supporting inter-cell mobility.

[0010] The present invention is proposed to solve the aforementioned problems, and aims to provide a system and method capable of ensuring the mobility of a host through high-speed handoff without service interruption by effectively performing network slicing updates in a software-based virtualized network device that supports network slicing, and by changing the network slice of the host in real time when a host assigned to a network slice is moving to an adjacent wireless cell.

[0011] The present invention relates to a network slicing update system through dynamic resource allocation and a method for guaranteeing host mobility using the same.

[0012] A network slicing update system through dynamic resource allocation according to the present invention includes an update request receiving unit that receives a network slicing update request, a host to be removed identification and resource release unit that identifies a host to be removed and releases resources according to the update request, and an additional host identification and resource allocation unit that identifies a host to be added and allocates resources.

[0013] The above-mentioned host identification and resource release unit identifies the hosts to be removed by comparing the set of hosts in the previous virtual private network with the set of hosts in the updated virtual private network.

[0014] The above-mentioned host identification and resource release unit identifies the host to be removed by using the difference between the set of hosts of the previous virtual private network and the set of hosts of the updated virtual private network.

[0015] The above-mentioned host identification and resource release unit deletes flow rules related to the above-mentioned host and releases unnecessary network resources from the virtual private network.

[0016] The above-mentioned host identification and resource release unit performs only flow rule deletion and retains network resources when the host to be removed is included in an edge switch connected to another host within a virtual private network.

[0017] The additional target host identification and resource allocation unit identifies the additional target host by using the host set of the updated virtual private network and the host set of the previous virtual private network.

[0018] The additional target host identification and resource allocation unit identifies the additional target host by using the difference between the set of hosts of the updated virtual private network and the set of hosts of the previous virtual private network.

[0019] The additional target host identification and resource allocation unit resets the central node when the virtual dedicated network tree is changed by the edge node of the additional target host.

[0020] A method for ensuring the mobility of a host using a network slicing update system through dynamic resource allocation according to the present invention includes (a) detecting the movement of a host registered in a network slice and (b) performing a handoff using a data link layer without using an IP address in relation to the movement of the host.

[0021] Step (a) above detects the movement of the host by receiving received electric field strength information from the base station and the host when the host corresponding to the user terminal moves.

[0022] Step (a) above detects the movement of the host by considering the handoff tracking start electric field strength level.

[0023] Step (a) above receives a request to prepare to delete the host from the first network slice to which the host currently belongs and a request to prepare to add the host to the second network slice to which the host will belong, in accordance with a change in the received electric field strength information.

[0024] Step (b) above moves the MAC address of the host in the MAC layer, which is a lower layer of the data link layer, by taking into account the reduction in the electric field strength level of the first base station corresponding to the first network slice and the increase in the electric field strength level of the second base station corresponding to the second network slice.

[0025] Step (b) above performs the handoff by considering the handoff electric field strength transition point level.

[0026] Step (b) above terminates the handoff by considering the received power of the signal sent from the first base station and the electric field strength level of the handoff tracking end point.

[0027] Step (b) above receives environmental variables including wireless transmission / reception field strength, interference, and noise from field equipment, learns the relationship between said environmental variables and handoff performance, and corrects the received field strength setting related to said handoff.

[0028] According to the present invention, in network slicing updates, instead of completely reconstructing the network tree, only the necessary parts are selectively updated, thereby making it possible to significantly reduce the update time by modifying only the changed parts.

[0029] According to the present invention, when updating network slicing, it is possible to efficiently manage hosts to be removed and hosts to be added, and efficiently recycle resources through the release of network resources of hosts to be removed and the allocation of additional resources required for new hosts, thereby minimizing the use of unnecessary resources and rapidly adding new resources to increase the efficiency of network updates.

[0030] According to the present invention, by releasing only the resources associated with the removed host and not affecting communication between other hosts, the effect of minimizing the impact on existing network traffic or communication paths during the network slicing update process is maintained, thereby maintaining network performance.

[0031] According to the present invention, by selectively processing only the parts requiring update during the network slicing update process and calculating and rapidly applying a new path, it is possible to improve the user's perceived quality of service by minimizing service latency and downtime, and to minimize negative impact on the user by designing the update process to be carried out within the service allowable range.

[0032] According to the present invention, network resources can be immediately reallocated when a new host is added or an existing host is removed, and the virtual network can be flexibly updated to respond dynamically to user requirements in response to the occurrence of new user requirements, and there is an advantage in being able to respond to a network environment that changes in real time.

[0033] According to the present invention, security rules and flow information related to each host are updated together when updating network slicing, thereby maintaining network isolation and security even after updating, and enabling stable network operation without security risks. Even after updating network slicing, resources of the removed host are completely released, and only resources for the new host are added, thereby enhancing security.

[0034] According to the present invention, by configuring a mobile communication network based on network slicing, latency is reduced through network slicing-based inter-cell handoff without passing through Layer 3, and there is an advantage of enabling seamless high-speed handoff when providing real-time services such as autonomous driving and telemedicine even on devices such as wireless LANs.

[0035] According to the present invention, by sharing network facilities at the layer 2 level and exchanging control rights between base stations, mobility control is possible within the company's network, enabling independent network operation, and independent movement between cells is supported, so no additional costs are incurred, thus having the advantage of excellent economic efficiency.

[0036] According to the present invention, by supporting handoff between dense wireless cells at layer 2, a large number of terminals can be guaranteed seamless connectivity regardless of IP while performance is guaranteed.

[0037] In the case of a wireless LAN built with a mesh-based Multi WiFi AP, there are limitations to real-time services due to latency issues arising from routing via wireless relay. However, according to the present invention, by configuring a Multi WiFi AP network based on a network slice method, it is possible to provide services even while moving between cells and to minimize dead zones without latency, thereby providing connection stability.

[0038] According to the present invention, by using formulas regarding handoff tracking points and handoff transition points, it is possible to self-monitor changes in cell coverage due to environmental changes (such as cell additions or seasonal changes in electric field strength) and update the handoff reception strength in real time through intelligent radio control and monitoring functions, thereby increasing the handoff success rate and minimizing human error caused by human intervention.

[0039] The effects of the present invention are not limited to those mentioned above, and other unmentioned effects will be clearly understood by those skilled in the art from the description below.

[0040] FIG. 1 illustrates the configuration of a network slicing update system through dynamic resource allocation according to an embodiment of the present invention.

[0041] FIG. 2 illustrates a selective virtual dedicated network update process (selective VDN reconfiguration) according to an embodiment of the present invention.

[0042] FIG. 3 illustrates a virtual dedicated network update algorithm according to an embodiment of the present invention.

[0043] FIG. 4 illustrates the update process of a selective virtual dedicated network according to an embodiment of the present invention.

[0044] FIG. 5 illustrates the configuration of a handoff system at the L2 layer based on network slicing according to an embodiment of the present invention.

[0045] FIG. 6 illustrates a high-speed handoff process based on network slicing according to an embodiment of the present invention.

[0046] FIG. 7 illustrates a network slicing-based handoff process according to an embodiment of the present invention.

[0047] FIG. 8 illustrates electric field strength tracking for soft handoff according to an embodiment of the present invention.

[0048] FIG. 9 illustrates the process of setting the initial electric field strength for a handoff according to an embodiment of the present invention.

[0049] FIG. 10 illustrates the electric field strength tracking and transition process for soft handoff according to an embodiment of the present invention.

[0050] FIG. 11 illustrates the operation process of an intelligent radio controller to increase the accuracy of a soft handoff formula according to an embodiment of the present invention.

[0051] FIG. 12 is a block diagram showing a computer system for implementing a method according to an embodiment of the present invention.

[0052] The aforementioned objectives of the present invention, as well as other objectives, advantages, and features, and the methods for achieving them, will become clear from the embodiments described in detail below together with the accompanying drawings.

[0053] However, the present invention is not limited to the embodiments disclosed below but can be implemented in various different forms, and the following embodiments are provided merely to easily inform those skilled in the art of the purpose, structure, and effects of the invention, and the scope of the present invention is defined by the description in the claims.

[0054] Meanwhile, the terms used in this specification are for describing the embodiments and are not intended to limit the invention. In this specification, the singular form includes the plural form unless specifically stated otherwise in the text. As used in this specification, "comprises" and / or "comprising" do not exclude the presence or addition of one or more other components, steps, actions, and / or elements to the mentioned components, steps, actions, and / or elements.

[0055]

[0056] In order to assist those skilled in the art in understanding, the background of the proposed invention and embodiments of the invention will be described below.

[0057] Software Defined Networking (SDN) is defined as a technology that separates the function of controlling network data flow from actual network equipment, allowing for centralized control and programming of the network. Network structures based on conventional technology follow a method where each network device operates independently and switches or routers constituting the network manage traffic individually. According to conventional technology, limitations in control become apparent as network complexity increases; however, Software Defined Networking makes it possible to resolve the issues regarding control limitations associated with conventional technology by dynamically managing network resources through a centralized controller. According to an embodiment of the present invention, a network slicing technology based on Software Defined Networking is proposed, which enables more efficient resource allocation and management in a virtualized network and has the effect of improving network flexibility and efficiency through selective network slicing updates.

[0058] Network slicing is defined as a technology that divides a physical network into multiple virtual networks (slices) so that each slice operates as an independent network. Network slicing is primarily used in 5G / 6G networks, and each slice needs to be customized to meet the requirements of specific services or applications. 5G networks are designed to meet various service requirements, such as ultra-low latency, high bandwidth, and high reliability, and each slice is allocated dedicated resources to meet these service requirements, thereby ensuring communication quality. According to an embodiment of the present invention, regarding network slicing updates, there is a technical feature that enables maximizing the efficiency of network resources, maintaining network quality, and satisfying dynamic service requirements by removing unnecessary resources within the slice and dynamically allocating new resources while maintaining the performance of the slice.

[0059] Network virtualization is defined as a technology that abstracts physical resources to enable their use as multiple virtual resources. Virtualization technology was developed for the efficient utilization of resources, and virtualized network equipment overcomes the limitations of physical equipment, allowing each user to utilize the resources as if they were using independent resources, even when multiple users share the same physical resources. According to an embodiment of the present invention, a system is proposed that enables the efficient allocation and updating of network resources by combining a software-defined network and network slicing in a virtualized network environment. According to an embodiment of the present invention, by effectively processing software updates for virtualized network devices, it is possible to maintain network performance without service interruption.

[0060] 5G / 6G networks are next-generation communication technologies developed with the goal of ultra-low latency, high reliability, and large-capacity data transmission, enabling the realization of various applications that were difficult to achieve in existing communication environments, such as autonomous driving, smart factories, and AR / VR. 5G networks were proposed based on the idea that various types of terminals must be able to maintain high-quality communication while moving, making mobility management a critical issue, and requiring each terminal to move smoothly between network slices. According to an embodiment of the present invention, by proposing a network slicing-based handoff technology to support terminal mobility in a 5G network, there are technical features that allow for natural switching between network slices when a terminal moves, and enable real-time mobility management and resource reallocation.

[0061] Network security is a critical element in network slicing and virtualization environments, and ensuring the safety of data transmission and protecting network resources in large-scale networks such as 5G is a critical task. According to conventional technology, physical security in networks was primarily emphasized; however, with the introduction of virtualization and software-defined networks, the scope of security threats has expanded. In virtualized environments, access control and data protection regarding network resources are even more critical issues. According to an embodiment of the present invention, a security mechanism is proposed that protects each slice independently and prevents unauthorized access to network resources by strengthening isolation and security between network slices. According to an embodiment of the present invention, a method is presented to minimize security threats during the network resource update process. Furthermore, by applying resilience technology that isolates network resources subject to security, allocates new resources, and performs slicing updates in the event of an intrusion attack in a network slice-guaranteed network, the effect of ensuring service resilience is achieved.

[0062] Automation technology is a technology that maximizes efficiency by automatically handling the allocation and management of network resources. In network slicing and virtualized network environments, dynamic allocation and real-time updating of resources are critical factors. As network complexity increases, manual management of network resources has reached its limits. To address this problem, automatic allocation and management of network resources can be performed by combining software-defined network and orchestration technologies. According to an embodiment of the present invention, by applying software-defined network-based network slicing technology, there are technical features that enable the automation of the update and allocation process of network resources and the efficient management of resources while maintaining network performance.

[0063]

[0064] According to an embodiment of the present invention, a network slicing update system is proposed for effectively performing network slicing updates in a software-based virtualized network device that supports network slicing.

[0065] In addition, a method is proposed to ensure the mobility of a host by changing the network slice of a host in real time when a host assigned to a network slicing is moving to an adjacent wireless cell through a network slicing update system according to an embodiment of the present invention, thereby performing high-speed handoff without service interruption.

[0066] According to an embodiment of the present invention, it is possible to maintain network performance and improve resource efficiency through dynamic allocation and updating of resources within a network slice. As 5G / 6G networks must be able to divide and manage resources through network slicing to meet various services and user requirements, it is possible to efficiently utilize resources and reduce waste of network resources by releasing unnecessary resources through dynamic allocation and deallocation of network resources.

[0067] According to an embodiment of the present invention, it is possible to safely update the software of a virtualized network device while minimizing service interruption. According to the prior art, service provision is interrupted or performance degradation occurs when updating software, whereas according to an embodiment of the present invention, network slicing updates are performed so that services unrelated to network devices and user terminals requiring slice changes are provided without interruption.

[0068] According to an embodiment of the present invention, it is possible to maintain service quality by smoothly performing network slice switching of a moving terminal. Since 5G / 6G networks aim to provide uninterrupted service even when a user terminal is moving, a mobility management function supports smooth switching between network slices even when the terminal is moving across the network.

[0069] According to an embodiment of the present invention, it is possible to manage and optimize traffic in real time by flexibly managing network slicing to meet various service requirements in a 5G network. Since the function of managing traffic occurring within a network slice in real time and redistributing resources according to the amount of traffic is important for maintaining network performance, it is possible to optimize network performance by effectively controlling traffic within a slice and dynamically allocating necessary resources through traffic monitoring and management functions.

[0070] According to the present invention, it is possible to maintain security between slices and minimize security threats that may occur during the network resource update process. By selectively controlling network slices of terminal / application services where cyber threats have been detected, the invention provides a security resilience method capable of improving the connection survivability of services by performing network isolation in response to cyber attacks and optimizing network / service recovery performance.

[0071]

[0072] In the following description, Network Slice (NS), Virtual Network, and Virtual Private Network (VDN) are used interchangeably.

[0073] FIG. 1 illustrates the configuration of a network slicing update system through dynamic resource allocation according to an embodiment of the present invention.

[0074] A network slicing update system through dynamic resource allocation according to an embodiment of the present invention includes an update request receiving unit (10) that receives a network slicing update request, a host to be removed identification and resource release unit (20) that identifies a host to be removed and releases resources, and an additional target host identification and resource allocation unit (30) that identifies an additional target host and allocates resources. The components according to an embodiment of the present invention may be provided as separate modules, or they may be provided as modules in which each function is combined. In addition, the aforementioned update request receiving unit (10), host to be removed identification and resource release unit (20), and additional target host identification and resource allocation unit (30) may be provided as components included in an SDN controller.

[0075] The host identification and resource release unit (20) for removing targets receives an update request and identifies the hosts to be removed by comparing the host set of the previous virtual private network with the host set of the updated virtual private network. At this time, the host identification and resource release unit (20) identifies the hosts to be removed by using the difference between the host set of the previous virtual private network and the host set of the updated virtual private network. The host identification and resource release unit (20) deletes the flow rules associated with the hosts to be removed and releases unnecessary network resources from the virtual private network. If the hosts to be removed are included in an edge switch connected to other hosts within the virtual private network, the host identification and resource release unit (20) performs only the deletion of flow rules and retains the network resources.

[0076] The additional target host identification and resource allocation unit (30) identifies additional target hosts using the host set of the updated virtual private network and the host set of the previous virtual private network. At this time, the additional target host identification and resource allocation unit (30) identifies additional target hosts using the difference set between the host set of the updated virtual private network and the host set of the previous virtual private network. The additional target host identification and resource allocation unit (30) allocates network resources required for additional target hosts. If the virtual private network tree is changed by the edge node of the additional target host, the additional target host identification and resource allocation unit (30) resets the center node.

[0077]

[0078] Hereinafter, the configuration of a network slicing update system through dynamic resource allocation according to an embodiment of the present invention will be described.

[0079] SDN Controller

[0080] The SDN controller acts as the central control unit of the network, managing all resources of the physical and virtual networks and controlling network traffic. The SDN controller collects information on hosts, switches, links, etc., in the physical network, configures and controls virtual networks, and manages network traffic in real time according to user requirements.

[0081] Data Plane

[0082] The data plane consists of physical network devices (switches, routers, etc.) that constitute the path through which actual data is transmitted. Through the data plane, traffic paths are established in the physical network, and packets are forwarded according to specifications set by the SDN controller.

[0083] Virtual Network Management System (Network Management System)

[0084] A virtual network management system is a system that manages virtual networks by dynamically creating, updating, and deleting them. It integrates with an SDN controller to automate virtual network control and allocate resources according to user requirements. The virtual network management system allocates resources used within the virtual network and performs dynamic adjustments based on network status.

[0085] Network Slicing Module

[0086] The network slicing module integrates with a virtual network management system and separates a single physical network into multiple virtual networks, with each slice serving as an independent network resource. The network slicing module can manage network traffic independently by dividing networks in response to various user needs and allocating dedicated resources to each slice. To enhance security, the network slicing module provides network isolation and enables secure data processing without interference between slices.

[0087] Resource Allocation Module

[0088] The resource allocation module dynamically allocates network resources required for the creation and updating of virtual networks. Responding to user demands, the module selects and allocates resources such as links, bandwidth, and switches necessary for the virtual network, thereby guaranteeing network performance and stability. The resource allocation module optimizes network performance by minimizing the use of unnecessary resources and efficiently reallocating available resources.

[0089] Network Tree Construction Module

[0090] The network tree configuration module constructs a network tree based on information received from the SDN controller. It calculates the most efficient path within the network and configures a shortest-path-based network tree connecting each host and switch.

[0091] Security and Policy Management Module

[0092] The Security and Policy Management Module maintains the security of virtual networks and manages network policies, applying security policies during network slicing and resource allocation. It performs security isolation, user authentication, and access control between virtual networks, ensuring the integrity and safety of network traffic. The Security and Policy Management Module provides whitelist-based network slicing security to restrict network access to only authorized users or devices.

[0093] Open Interface

[0094] An open interface is an interface that enables external systems or user / network administrators to easily create and manage virtual networks.

[0095] Through the open interface, users can easily perform requests for network creation, updating, or deletion, resource allocation, and network status monitoring. The open interface also enables real-time visual verification of network status and performance, thereby increasing management efficiency.

[0096]

[0097] The following describes requirements related to selective updating of a network slice according to an embodiment of the present invention.

[0098] After network slicing updates, all hosts within the updated virtual private network must be able to communicate seamlessly with each other, thereby enabling the updated virtual private network to continuously provide uninterrupted connectivity between hosts.

[0099] Regarding end-to-end paths between updated virtual private network hosts, necessary bandwidth support is required. The updated virtual private network must provide sufficient network capacity and performance to meet service level agreements or user expectations.

[0100] Communication between previous virtual dedicated network hosts / services, excluding deleted hosts, must not be affected by the update, and network connectivity and performance must be maintained for hosts / services unaffected by the update.

[0101] This means that the update process of a virtual private network must be performed within the service acceptance range and that the update must not significantly degrade the quality of service provided to users. The update needs to be performed in a manner that minimizes the impact on ongoing network services.

[0102]

[0103] In the following, with reference to FIG. 2, a selective virtual dedicated network update process (selective VDN reconfiguration) will be described.

[0104] A central node is selected (S210).

[0105] The central node with the highest closeness centrality within the virtual private network to be updated is identified. Closeness centrality is an indicator in network analysis that measures how close a specific node is to other nodes; it is calculated based on the average distance from one node to every other node within the network and can be used to determine how quickly information can be transmitted from that node to others. The central node is the node that can reach other nodes via the shortest path within the network and plays the most critical role when updating the virtual private network. If the network has not changed significantly, the process of reselecting the central node may be omitted.

[0106] Identify the host to be removed and perform resource release (S220).

[0107] A host (Hr) to be removed is identified based on an update request. According to an embodiment of the present invention, the host set (Hp) of the previous virtual private network and the host set (Hv) of the updated virtual private network are compared to determine which of the previous hosts are no longer needed. The network resources associated with the host identified as the target for removal are released by deleting the flow rules associated with the host and releasing unnecessary network resources from the virtual private network. If the host is still included in an edge switch connected to other hosts within the virtual private network, only the host information and flow rules are deleted, while the network resources are retained.

[0108] Identify the hosts to be added and perform resource allocation (S230).

[0109] The host (Ha) to be added is identified by comparing the host set (Hv) of the updated virtual private network with the host set (Hp) of the previous virtual private network. Network resources required for the host to be added are allocated, a new path is established, and resources necessary for communication with the host are allocated. If the host is already included in an existing path, existing resources are used without establishing a separate additional path.

[0110] The central node of the virtual dedicated network is re-selected (S240).

[0111] If there is a change in the virtual private network topology, the central node is re-selected. By re-selecting the most suitable central node for the new network structure, an efficient network configuration can be maintained even after the virtual private network update.

[0112]

[0113] FIG. 3 illustrates a virtual private network update algorithm according to an embodiment of the present invention, and FIG. 4 illustrates an example of a selective virtual private network update process according to an embodiment of the present invention.

[0114] Hp (the set of hosts in the previous virtual private network) is {h1, h2, h3, h4, h7}, Hv (the set of hosts in the updated virtual private network) is {h2, h3, h5, h6, h8}, Ha (the set of hosts to be added) is {h5, h6, h8}, and Hr (the set of hosts to be removed) is {h1, h4, h7}.

[0115] As described above, in step S220, hosts to be removed are identified and resource release is performed. First, host Hr (set of hosts to be removed) of the removed virtual private network must be found, and network resources associated with Hr (set of hosts to be removed) are released from the virtual private network. Hr (set of hosts to be removed) is determined by comparing the requested VDN host set with the previous VDN host set Hp. Given Hv (set of hosts in the updated virtual private network) and Hp (set of hosts in the previous virtual private network), Hr (set of hosts to be removed) is defined as the difference set obtained by subtracting Hv (set of hosts in the updated virtual private network) from Hp (set of hosts in the previous virtual private network). Referring to Figure 4, since Hp (the host set of the previous virtual private network) is {h1, h2, h3, h4, h7} and Hv is {h2, h3, h5, h6, h8}, Hr (the host set to be removed) is indicated as {h1, h4, h7}. If Hr (the host set to be removed) is empty, step S220 is not required, and if Hr (the host set to be removed) is identified, all flow rules associated with Hr (the host set to be removed) are removed from the SDN nodes within the virtual private network. Additionally, network resources for Hr (the host set to be removed) must also be released from the virtual private network. However, if an edge node nh connected to Hr (the host set to be removed) is included in N (Hv, the host set of the updated virtual private network), this procedure is unnecessary because the edge node is also used by hosts in other virtual private networks of Hv (the host set of the updated virtual private network). Therefore, only the flow rules associated with the removed hosts (h4, h7) are removed.If an edge node nh connected to Hr (the set of hosts to be removed) is not included in N (Hv, the set of hosts in the updated virtual private network), i.e., if it is like h1, network resources associated with the removed host, such as edge nodes, are released. Since nodes and links associated with the remaining hosts in the virtual private network may be removed together if they are included in the path between the edge node and the central node of the removed host, the shortest path between nc and N (Hp) is calculated for all Hp (the set of hosts in the previous virtual private network) of the previous virtual private network, and the calculated path is merged into the updated virtual private network.

[0116] As described above, in step S230, the hosts to be added are identified and resource allocation is performed. In step S230, the added host Ha (hosts to be added) is processed. First, the set of hosts Ha in the added virtual private network is found, and network resources are allocated for Ha (hosts to be added). Given Hv (set of hosts in the updated virtual private network) and Hp (set of hosts in the previous virtual private network), Ha (hosts to be added) is defined as the difference set obtained by subtracting Hv (set of hosts in the updated virtual private network) from Hp (set of hosts in the previous virtual private network), and Ha (hosts to be added) is denoted as {h5, h6, h8}. If Ha (hosts to be added) is empty, there is no need to perform step S230 for the added hosts. The reconfiguration procedure for Ha (hosts to be added) is simpler than that for Hr (set of hosts to be removed). After finding a new shortest path between the central node nc and N(Ha) in the abstracted network, it is merged into the virtual private network. If the edge node nh of the added host already belongs to T, there is no need to merge the path associated with nh. Therefore, the reconfiguration procedure for Ha (the host to be added) is performed after the reconfiguration of Hr (the set of hosts to be removed). If T changes, a new central node nc is selected again based on the updated virtual private network. Regarding processing time, the maximum number of shortest path calculations for each step can be expressed as |N(Hp)| - |N(Hh)| and |N(Ha)|, respectively. In a real-world environment, since almost all users reside at the same site (e.g., headquarters, branch offices, key partners), situations involving the addition and removal of edge nodes do not occur frequently after the virtual private network has been created with the edge nodes included.In other words, the reconfiguration of a virtual private network can be completed by changing the host set of the virtual private network, except in cases where new path calculations are required.

[0117]

[0118] The application of cybersecurity resilience according to an embodiment of the present invention is described below. According to an embodiment of the present invention, network slicing (NS) updates are performed based on the detection of network slice change factors.

[0119] According to an embodiment of the present invention, in a network slice guarantee network connected to a 5G core, intrusion attacks are integrated and monitored, survivability is guaranteed, and a resilience method for security response (isolation, service recovery, etc.) is provided upon detection of an intrusion attack, thereby removing terminals and application services that have become unnecessary during the network slicing reconfiguration process, releasing network resources used for this purpose, and efficiently reallocating new resources to ensure network flexibility through service recovery.

[0120] According to an embodiment of the present invention, terminals and application services to be removed for security purposes are identified, and network resources related to a virtual private network are released. Terminals / application services to be removed within the virtual private network are queried, and network resources (including network equipment flows) associated with them are released from the virtual private network. At this time, as described above, the network resource release is performed by comparing the requested set of virtual private network terminals / application services with the previous set of virtual private network terminals / application services. By removing terminals / application services that have become unnecessary during the virtual private network reconfiguration process and releasing related network resources, it is possible to efficiently reallocate resources and ensure network flexibility.

[0121] According to an embodiment of the present invention, terminals / application services to be added for service maintenance are identified, and network resource allocation related to the virtual private network is performed. A set of terminals / application services to be added to the virtual private network to support new user requirements is identified, and network resources necessary for them are allocated. Through this, the virtual private network can flexibly respond to new user requirements, and dynamic updating of the virtual private network is possible.

[0122] According to an embodiment of the present invention, a network slicing-based handoff implementation method is proposed that supports high-speed handoff between cells while guaranteeing the performance (QoS) of the required service regardless of IP even after movement, unlike existing devices in a small cell environment providing high-speed data services. Furthermore, according to an embodiment of the present invention, a method is proposed to track the received electric field strength in a high-speed service cell in a cell overlapping section where handoff occurs and to determine the electric field reception strength for handoff. According to an embodiment of the present invention, it is possible to independently provide uninterrupted data services to a user terminal regardless of IP, even when the service cell size changes due to a surge in users during movement.

[0123]

[0124] Hereinafter, with reference to FIG. 5, the configuration of a network slicing-based handoff system at the L2 layer according to an embodiment of the present invention will be described.

[0125] According to an embodiment of the present invention, a network slicing-based handoff system is a structure for virtualizing / abstracting a wireless terminal and a communication network resource connecting it, wherein software functions included in the hardware are implemented as software in a central control unit, and the hardware is implemented as white box hardware or COTS (Commercial, off-the-shelf) servers, etc., thereby enabling the system to escape from issues of component replacement and manufacturer dependency.

[0126] In the structure according to an embodiment of the present invention, the basic hardware configuration includes a Software Defined Network (SDN)-based network central control unit (SDN controller, 100), a wireless access device (200a, 200b), and an SDN switch (network device, 300) responsible for data transmission in the network. Communication between these components is separated into a data plane path and a control plane path to perform functions.

[0127] In a network, the data plane performs the role of delivering actual traffic from network devices (including functions for receiving, forwarding, and transmitting packets). The data plane moves data along the network's physical path or, if necessary, a virtual dedicated path (network slice).

[0128] The control plane performs the role of managing and controlling the traffic flow of sessions and networks. The control plane determines the network topology inside the vehicle, sets up network slices (paths), and applies handoff policies. The control plane runs on the SDN controller (100) and issues commands to wireless access devices (200a, 200b), SDN switches (300), user terminals (UE), and other network devices to ensure that the data plane operates correctly.

[0129] According to an embodiment of the present invention, it is possible to connect networks and transmit data at high speed by performing handoff using only the data link layer (Layer 2) of the OSI 7 layers without using IP. According to an embodiment of the present invention, a network slice, which is a logical network dedicated to a wireless terminal, is configured by separating the data plane and the control plane, and data transmission is performed along the network slice to ensure L2-based high-speed handoff, transmission speed (bandwidth), communication delay, etc., thereby ensuring service performance (QoS) for wireless communication of the terminal.

[0130] The SDN controller (100) includes a network application unit (110), a network slicing creation and control unit (120), an intelligent radio control and monitoring unit (130), and a control signal transmission port (140).

[0131] The network application unit (110) performs the function of virtualizing and adding network functions and supports the designer or operator in virtualizing and adding network functions such as DHCP, firewall, and NAT.

[0132] The network slice creation and control unit (120) performs terminal and network device authentication, session setup, and path creation functions, and performs the function of dynamically creating a virtual private network (virtual private path, network slice) from the terminal to the network service end on a physical Ethernet cable line. The network slice creation and control unit (120) controls and manages data through the virtual private network (network slice) according to the request of the terminal, and guarantees the QoS of data traffic in the wired and wireless network to perform dynamic virtual path creation, modification, management, device authentication, and session setup.

[0133] The intelligent radio control and monitoring unit (130) monitors environmental variables such as wireless transmission and reception field strength, interference, and noise, and improves the accuracy of the measured values ​​by providing feedback to the base station and terminal to determine the performance of a real-time handoff.

[0134] The control signal transmission port (140) transmits the control signal.

[0135] Software that performs the main functions of the network (path calculation, routing) is executed by the SDN controller (100). The SDN switch (300) is a data transmission switch connected to the SDN controller (100) via a control plane communication channel and uses a flow table of the data link layer for data transmission. It also performs data transmission functions through Ethernet ports of the wired and wireless physical layers. This SDN switch (300) can be implemented in a COTS server or a whitebox switch.

[0136] The wireless access device (200a, 200b) is a mobile communication base station or wireless LAN access access point (AP) device for providing mobile communication services, receives wireless data from a user terminal (UE), transmits it to an SDN switch (300), and provides handoff tracking and reception field monitoring functions.

[0137]

[0138] Hereinafter, with reference to FIG. 6, a high-speed handoff process based on network slicing according to an embodiment of the present invention will be described, specifically, a MAC address registration procedure and a host update procedure in a network slice when performing a handoff due to inter-cell movement in a wireless device.

[0139]

[0140] Referring to FIG. 6, the user terminal (UE) moves from A, which is a wireless AP1 cell, to B, which overlaps with the wireless AP cell. The SDN controller (100) updates information regarding the movement of the terminal between cells in real time.

[0141]

[0142] Hereinafter, with reference to FIG. 7, an algorithm for performing a handoff when a user terminal (UE) moves from wireless AP1 cell A to section B, which overlaps with the wireless AP cell, is described. Below, the handoff process for maintaining network slicing services during inter-cell movement is described step-by-step.

[0143] Electric field strength tracking start phase (S710)

[0144] The user terminal (UE) begins tracking the field strength of wireless AP1. Wireless AP1 sends a field strength tracking detection request and a slice host deletion readiness request to the SDN controller, and receives an ACK response from the SDN controller.

[0145] Step to verify increase in electric field strength level of wireless AP2 (S720)

[0146] When the increase in the electric field strength level of the wireless AP2 reaches a threshold, the user terminal (UE) notifies the SDN controller and receives an ACK response from the SDN controller.

[0147] Slice host addition preparation step (S730)

[0148] The user terminal (UE) tracks the field strength of wireless AP2, and the SDN controller sends a request to wireless AP2 to prepare to add slice hosts and receives an ACK response.

[0149] Electric field strength level reduction verification step (S740)

[0150] When the reduction in the electric field strength level of wireless AP1 reaches a threshold, the user terminal (UE) notifies the SDN controller and receives an ACK response from the SDN controller.

[0151] Handoff settings (S750)

[0152] The User Equipment (UE) initiates a handoff from Wireless AP1 to Wireless AP2. The SDN controller checks the monitoring results for environmental variables such as wireless transmission and reception field strength, interference, and noise, and verifies the field strength tracking value using a pre-configured formula to set up the handoff.

[0153] MAC address transfer step (S760)

[0154] The MAC address of the user terminal (UE) moves from wireless AP1 to wireless AP2. The SDN switch, under the control command of the SDN controller, releases the MAC address of the user terminal (UE) from Port 1 and registers the MAC address of the user terminal (UE) on Port 2.

[0155] Slice host movement step (S770)

[0156] The slice host of the user terminal (UE) moves from the first slice to the second slice. The SDN controller releases the host of the user terminal (UE) from the first slice and registers the host of the user terminal (UE) in the second slice.

[0157] Electric field strength tracking termination step (S780)

[0158] When the field strength of the wireless AP2 reaches a preset handoff termination field strength, the user terminal (UE) requests to terminate tracking, and the SDN controller notifies the termination of field strength tracking.

[0159] An SDN controller according to an embodiment of the present invention checks monitoring information using an intelligent radio control and monitoring unit, and sets the received electric field value and electric field strength tracking value of the handoff transition point for handoff setup between the base station and the user terminal.

[0160]

[0161] Hereinafter, with reference to FIG. 8, a formula for setting the received electric field value and the electric field strength tracking value is described, and the formula according to the embodiment of the present invention is loaded as a program into the intelligent radio control and monitoring unit of the SDN controller and operates.

[0162] ① The point is the electric field strength level at which handoff tracking begins (P r1 As such, the formula for determining this is as shown in [Mathematical Formula 1] below.

[0163] [Mathematical Formula 1]

[0164]

[0165] At this time, Is And, silver is, represents the correction loss. The correction loss (offset) is a value that corrects the loss by receiving feedback from the intelligent radio control and monitoring unit.

[0166] The definition of the symbol in [Mathematical Formula 1] is as follows.

[0167] : Electric field strength (dBm) received by the terminal for the signal transmitted by the wireless AP1 base station

[0168] : Power transmitted from wireless AP1 base station (dBm)

[0169] : Wireless AP1 base station's transmitting antenna gain (dBi)

[0170] : Terminal's receiving antenna gain (dBi)

[0171] : Transmission power loss in free space (dB)

[0172] : Transmission power loss (dB) according to modulation method

[0173] : Correction loss based on field environment (0~3dB)

[0174] f: Frequency (Hz)

[0175] d: Distance between antennas (m)

[0176] C: Speed ​​of light

[0177] M: Number of symbols according to modulation scheme

[0178] ② The point is the point where the service cell changes after handoff tracking (the point where the electric field strength rises or falls), and the handoff electric field strength transition point level ( The formula for determining ) is as follows [Equation 2].

[0179] [Mathematical Formula 2]

[0180]

[0181] The definition of the symbol in [Mathematical Formula 2] is as follows.

[0182] Ch: Channel transmission capacity (bps)

[0183] B: Channel allocation bandwidth (Hz)

[0184] : Received signal power (W) of wireless AP1 base station

[0185] : Received signal power of wireless AP2 base station (W) (becomes the noise power)

[0186] ③ The service cell changes after handoff tracking, and the field strength level of the point where handoff tracking ends after the field strength transition ( The formula for determining ) is as follows [Equation 3].

[0187] [Mathematical Formula 3]

[0188]

[0189] 3 is the received power of the signal sent from the wireless AP1 base station at point 3, and corresponds to the tracking end point (dBm) for the received signal field strength of the wireless AP1 base station.

[0190] ④ The point is the location (distance) where handoff tracking was initiated from the base station, serving as the initial handoff distance for measuring environmental variables and designing test software during initial cell design ( ) is a setting value and is determined according to the following [Equation 4].

[0191] [Mathematical Formula 4]

[0192] (step, )

[0193] At this time, Is am.

[0194] The definition of the symbol in [Mathematical Formula 4] is as follows.

[0195] : As a receiving power tracking point for handoff, the distance (m) from the base station to the starting point for handoff tracking

[0196] As mentioned above, is a setting value for determining the handoff start point and operating an internal test program during cell design. According to an embodiment of the present invention, the handoff is optimized by calculating electric field strength and distance for network slicing-based handoff settings.

[0197]

[0198] Hereinafter, with reference to FIG. 9, the process of setting the initial electric field strength for performing a handoff according to an embodiment of the present invention will be explained.

[0199] FIG. 9 illustrates an initial setup process for a handoff during a network slicing-based handoff process according to an embodiment of the present invention.

[0200] Request for initialization of field strength of base station and terminal for handoff (S910)

[0201] When designing the initial cell, regarding the location of the starting point of the cell overlap section, the base station and the terminal are the distance to the point where handoff tracking begins ( Requests configuration for ) to the SDN controller.

[0202] Set receiving power tracking point (S920)

[0203] The SDN controller configures the receive power tracking point for the handoff and notifies the base station of the configuration result. The SDN controller receives a configuration request from the base station for reference values ​​related to the handoff field strength transition.

[0204] Setting electric field strength in the overlapping section (S930)

[0205] The SDN controller determines the electric field strength of the handoff tracking start point during the handoff process ( ), electric field strength at the handoff transition point ( ), electric field strength at the handoff tracking end point ( Complete the settings.

[0206] Notification of setup completion (S940)

[0207] The SDN controller notifies the base station that the field strength setting is complete, and the user terminal receives the notification of setting completion through the base station.

[0208]

[0209] According to an embodiment of the present invention, after an initial setting process is performed using result values ​​for setting electric field strength for handoff, the movement of the terminal is recognized and an electric field strength tracking and transition process for handoff is performed, which is explained with reference to Fig. 10 below.

[0210] User terminal movement detection (S1010)

[0211] The base station and the SDN controller detect the movement of the user terminal through changes in the terminal's electric field strength and request electric field strength tracking for handoff.

[0212] The user terminal and the base station refer to the electric field strength values ​​in the pre-configured cell overlap section according to the initial settings, and transmit the values ​​measured in real time to the intelligent radio control and monitoring unit.

[0213] Tracking level recognition at base station cell boundary point (S1020)

[0214] While the user terminal is moving, the location of the base station cell boundary point ( Electric field strength at the handoff tracking start point in ) ) recognizes the level.

[0215] Service cell change at handoff electric field strength transition point (S1030)

[0216] While the user terminal is moving, the base station's received electric field strength transition level ( It recognizes ) and moves the existing MAC address and network slice host information to the changed service cell to change the service cell.

[0217] Termination of electric field strength tracking due to service cell change (S1040)

[0218] As the service cell change of the user terminal is completed, the electric field strength reaches the electric field strength tracking end level ( When it reaches ), the handoff process is finally terminated.

[0219]

[0220] Hereinafter, with reference to FIG. 11, the process of improving the accuracy of the real-time formula determination value of the intelligent radio control and monitoring unit according to an embodiment of the present invention will be described. The intelligent radio control and monitoring unit included in the SDN controller performs an operation to improve the accuracy of the soft handoff formula in real time.

[0221] Acquisition of base station surrounding environment variables (S1110)

[0222] Environmental variables such as received electric field strength, interference, and noise are measured using measuring equipment deployed at the site.

[0223] Handoff related information collection (S1120)

[0224] During the handoff process resulting from the movement of the user terminal, the location, speed, electric field strength, etc., of the moving terminal are collected in real time to update the data.

[0225] Machine learning algorithm application (S1130)

[0226] Using machine learning algorithms, the relationship between environmental variables and handoff performance is learned, and a more accurate formula is derived to optimize the handoff formula.

[0227] Perform virtual test (S1140)

[0228] By utilizing the virtual test program included in the SDN controller, tests on handoff formulas are performed in various virtual environments, such as cities, suburbs, and indoors, and accuracy verification is conducted under various scenarios.

[0229] Check for errors or performance degradation and finish handoff formula correction (S1150)

[0230] If errors or performance degradation factors are detected during the handoff process, data related to the handoff failure rate, transmission speed reduction, etc., are analyzed, and supplements are made to the handoff formulas and result values. If errors or performance degradation are detected, the aforementioned processes S1120 to S1140 are repeatedly performed. According to an embodiment of the present invention, it is possible to improve the accuracy of the handoff formula result values ​​through the aforementioned processes.

[0231]

[0232] A method for ensuring the mobility of a host using a network slicing update system through dynamic resource allocation according to an embodiment of the present invention includes (a) detecting the movement of a host registered in a network slice and (b) performing a handoff using a data link layer without using an IP address in relation to the movement of the host.

[0233] (a) When the host corresponding to the user terminal moves, the base station and the host receive received electric field strength information to detect the movement of the host.

[0234] (a) Step detects the movement of the host by considering the handoff tracking start electric field strength level.

[0235] (a) Step receives a request to prepare to delete the host from the first network slice to which the host currently belongs and a request to prepare to add the host to the second network slice to which the host will belong, in accordance with the change in the received electric field strength information.

[0236] (b) Step (b) moves the MAC address of the host in the MAC layer, which is a lower layer of the data link layer, by taking into account the reduction in the electric field strength level of the first base station corresponding to the first network slice and the increase in the electric field strength level of the second base station corresponding to the second network slice.

[0237] (b) Step performs the handoff by considering the handoff electric field strength transition point level.

[0238] (b) Step (b) terminates the handoff by considering the received power of the signal sent from the first base station and the electric field strength level of the handoff tracking end point.

[0239] (b) Step (b) receives environmental variables including wireless transmission / reception field strength, interference, and noise from field equipment, learns the relationship between said environmental variables and handoff performance, and corrects the received field strength setting related to said handoff.

[0240] FIG. 12 is a block diagram showing a computer system for implementing a method according to an embodiment of the present invention.

[0241] Referring to FIG. 12, a computer system (1300) may include at least one of a processor (1313), memory (1330), an input interface device (1350), an output interface device (1360), and a storage device (1340) that communicate via a bus (1370). The computer system (1300) may also include a communication device (1320) coupled to a network. The processor (1310) may be a central processing unit (CPU) or a semiconductor device that executes instructions stored in memory (1330) or storage device (1340). Memory (1330) and storage device (1340) may include various forms of volatile or non-volatile storage media. For example, memory may include read-only memory (ROM) and random access memory (RAM). In the embodiments of this description, memory may be located inside or outside the processor, and memory may be connected to the processor through various known means. Memory is a volatile or non-volatile storage medium of various forms, and for example, memory may include read-only memory (ROM) or random access memory (RAM).

[0242] Accordingly, embodiments of the present invention may be implemented as a method implemented on a computer or as a non-transient computer-readable medium storing computer-executable instructions. In one embodiment, when executed by a processor, the computer-readable instructions may perform a method according to at least one aspect of the present description.

[0243] The communication device (1320) can transmit or receive wired or wireless signals.

[0244] In addition, the method according to an embodiment of the present invention may be implemented in the form of program instructions that can be executed through various computer means and may be recorded on a computer-readable medium.

[0245] The above computer-readable medium may include program instructions, data files, data structures, etc., either individually or in combination. The program instructions recorded on the computer-readable medium may be specially designed and configured for embodiments of the present invention, or they may be known and available to a person skilled in the art of computer software. The computer-readable recording medium may include a hardware device configured to store and execute program instructions. For example, the computer-readable recording medium may be magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; ROM; RAM; flash memory, etc. The program instructions may include not only machine code, such as that generated by a compiler, but also high-level language code that can be executed by a computer through an interpreter, etc.

[0246] Although embodiments of the present invention have been described in detail above, the scope of the present invention is not limited thereto, and various modifications and improvements by those skilled in the art using the basic concept of the present invention as defined in the following claims also fall within the scope of the present invention.

Claims

1. A update request receiver that receives a network slicing update request; A host to be removed identification and resource release unit that identifies a host to be removed and releases resources in accordance with the above update request; and Additional target host identification and resource allocation unit that identifies additional target hosts and allocates resources A network slicing update system through dynamic resource allocation including 2. In Paragraph 1, The above-mentioned host identification and resource release unit identifies the hosts to be removed by comparing the set of hosts of the previous virtual private network with the set of hosts of the updated virtual private network. Network slicing update system through dynamic resource allocation.

3. In Paragraph 2, The above-mentioned host identification and resource release unit identifies the host to be removed by using the difference set between the host set of the previous virtual private network and the host set of the updated virtual private network. Network slicing update system through dynamic resource allocation.

4. In Paragraph 1, The above-mentioned host identification and resource release unit deletes flow rules related to the above-mentioned host and releases unnecessary network resources from the virtual private network. Network slicing update system through dynamic resource allocation.

5. In Paragraph 4, The above-mentioned host identification and resource release unit performs only flow rule deletion and retains network resources when the above-mentioned host to be removed is included in an edge switch connected to another host within a virtual private network. Network slicing update system through dynamic resource allocation.

6. In Paragraph 1, The above additional target host identification and resource allocation unit identifies the additional target host by using the host set of the updated virtual private network and the host set of the previous virtual private network. Network slicing update system through dynamic resource allocation.

7. In Paragraph 6, The additional target host identification and resource allocation unit identifies the additional target host by using the difference set between the host set of the updated virtual private network and the host set of the previous virtual private network. Network slicing update system through dynamic resource allocation.

8. In Paragraph 1, The above additional target host identification and resource allocation unit resets the central node when the virtual private network tree is changed by the edge node of the above additional target host. Network slicing update system through dynamic resource allocation. 9.(a) detecting the movement of a host registered in a network slice; and (b) A step of performing a handoff using the data link layer without using an IP address in relation to the movement of the above host A method for guaranteeing host mobility using a network slicing update system including dynamic resource allocation.

10. In Paragraph 9, The above step (a) involves receiving received electric field strength information from the base station and the host when the host corresponding to the user terminal moves, thereby detecting the movement of the host. A method for guaranteeing host mobility using a network slicing update system through dynamic resource allocation.

11. In Paragraph 10, The above step (a) detects the movement of the host by considering the handoff tracking start electric field strength level. A method for guaranteeing host mobility using a network slicing update system through dynamic resource allocation.

12. In Paragraph 10, The above step (a) involves receiving a request to prepare to delete the host from the first network slice to which the host currently belongs and a request to prepare to add the host to the second network slice to which the host will belong, in accordance with a change in the received electric field strength information. A method for guaranteeing host mobility using a network slicing update system through dynamic resource allocation.

13. In Paragraph 12, Step (b) above involves moving the MAC address of the host in the MAC layer, which is a lower layer of the data link layer, by taking into account the reduction in the electric field strength level of the first base station corresponding to the first network slice and the increase in the electric field strength level of the second base station corresponding to the second network slice. A method for guaranteeing host mobility using a network slicing update system through dynamic resource allocation.

14. In Paragraph 13, Step (b) above performs the handoff by considering the handoff electric field strength transition point level. A method for guaranteeing host mobility using a network slicing update system through dynamic resource allocation.

15. In Paragraph 12, Step (b) above terminates the handoff by considering the received power of the signal sent from the first base station and the electric field strength level of the handoff tracking end point. A method for guaranteeing host mobility using a network slicing update system through dynamic resource allocation.

16. In Paragraph 9, The above step (b) involves receiving environmental variables including wireless transmission and reception field strength, interference, and noise from field equipment, learning the relationship between said environmental variables and handoff performance, and correcting the received field strength setting related to said handoff. A method for guaranteeing host mobility using a network slicing update system through dynamic resource allocation.