5G MEC Application Containers With SID-Based Slice Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of securely orchestrating Mobile Edge Compute (MEC) application deployment and 5G slice creation is exacerbated by difficulties in maintaining slicing isolation when access occurs from different points of the 5G architecture, particularly in controlling access through the 5G backhaul network.
Innovation Solution
A method involving the definition of a backhaul routing policy and MEC layer access policy, using segment identifiers (SID) to associate MEC applications with segment routing tunnels, ensuring secure access control through the 5G network by enforcing these policies at various network nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network slicing isolation is implemented to secure MEC application deployment, then security and isolation between slices are improved, but device complexity and orchestration difficulty increase
Solution Approach 1:
The patent introduces a Network Slice Selection Function (NSSF) as an intermediary component that manages slice selection and orchestration. This mediator handles the complex interactions between MEC applications and network slices, centralizing the orchestration logic and reducing overall system complexity while maintaining robust slicing isolation.
Solution Approach 2:
The patent segments the network into distinct slices with unique identifiers (S-NSSAI) and isolates MEC applications within specific slices. By dividing the network infrastructure into separable, independently managed segments, the system achieves reliable isolation between slices while allowing each segment to be orchestrated independently, thus managing complexity through modularization.
2Reliability
If access control policies are enforced at multiple network nodes to secure MEC application access, then security against unauthorized access is improved, but processing time and system overhead increase
Solution Approach 1:
The patent implements preliminary authentication and authorization by establishing access control policies at the network slice level before actual MEC application access occurs. The NSSF pre- validates user credentials and determines appropriate slice assignments in advance, so that when access requests are made to MEC applications, the authentication process is expedited since preliminary checks have already been performed.
Solution Approach 2:
The system implements self-service mechanisms where the network infrastructure automatically enforces access control policies without requiring manual intervention at each access point. Once initial authentication is complete, the system uses automated policy enforcement and slice isolation mechanisms that operate autonomously, reducing both processing time and operational overhead while maintaining security.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
Systems, methods, and computer-readable media for the secure creation of application containers for 5G slices. A MEC application in a MEC layer of a 5G network can be associated with a specific network slice of the 5G network. A backhaul routing policy for the MEC application can be defined based on the association of the MEC application with the specific network slice of the 5G network. Further, a SID for the MEC application that associates the MEC application with a segment routing tunnel through a backhaul of the 5G network can be generated. A MEC layer access policy for the MEC application can be defined based on the SID for the MEC application. As follows, access to the MEC application through the 5G network can be controlled based on both the backhaul routing policy for the MEC application and the MEC layer access policy for the application.