Cloud Slice Connectivity Manager for Automated Network Slicing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The management of connectivity between mobile apps and services and cloud environments is complex and lacks automation, leading to security concerns and inefficiencies, especially with the rollout of 5G network slicing.
Innovation Solution
A slice-connectivity manager is implemented as a virtual software within a customer's Virtual Private Cloud (VPC) in the cloud provider's cloud, which connects to a cloud-slice management API. This manager allows customers to authenticate, order, modify, and terminate Network as a Service (NaaS) products without sharing customer cloud account credentials, enhancing security and simplifying administration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple administration points (cloud provider, network operator, MDM) are used to manage connectivity, then comprehensive service management is achieved, but system complexity and difficulty of ensuring consistency increase
Solution Approach 1:
The patent introduces a cloud-based network slice management system as an intermediary layer between the cloud provider, network operator, and MDM. This system provides unified APIs and automated workflows that coordinate actions across all administration points, reducing complexity while maintaining comprehensive service management capability
Solution Approach 2:
The management system is designed to perform multiple functions across different administration domains through a single unified interface. It can manage network slice provisioning, configuration, monitoring, and termination across cloud, network, and device layers, eliminating the need for separate administration points
2Reliability
If manual configuration and direction are required for VPN setup, then security can be controlled, but automation and speed are reduced
Solution Approach 1:
The system enables automated self-service VPN configuration where the cloud-based management system automatically provisions network slices, configures VPN tunnels, and coordinates with MDM devices without requiring manual intervention. Security policies are pre-defined and automatically applied, maintaining security control while achieving full automation
Solution Approach 2:
Security policies, VPN configurations, and network slice parameters are pre-configured and validated before deployment. The system performs preliminary security checks and automatically applies approved configurations, ensuring security requirements are met while enabling rapid automated setup
3Ease of operation
If customer cloud account credentials are shared with network provider, then service integration is simplified, but security level is reduced
Solution Approach 1:
The patent introduces a cloud-based management system as a secure intermediary that handles all authentication and credential management. Customer credentials never leave the customer's cloud account, while the management system uses secure token-based authentication and API key mechanisms to enable service integration without credential sharing
Solution Approach 2:
The system segments authentication and authorization functions into separate secure modules. Different levels of access are provided through role-based access control (RBAC), where the management system receives limited, specific permissions rather than full customer credentials, maintaining security while enabling integration
4Ease of operation
If VPN secrets (usernames, passwords) are exchanged between parties, then connection can be established, but security risk and manual effort increase
Solution Approach 1:
The system replaces manual exchange of VPN secrets with automated cryptographic key management. Public key infrastructure (PKI) and certificate-based authentication are used instead of traditional username/password mechanisms. Secrets are generated, exchanged, and managed automatically through secure APIs, eliminating manual handling while establishing connections
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and system for setting up a network slice in a network between a UE and a VPC of a customer within the cloud of a cloud provider comprising the following steps: Providing a slice-connectivity manager and a connectivity-management entity, wherein a cloud-slice management API of the connectivity-management entity offers available network slice specifications of the network to the slice-connectivity manager, wherein a first network slice specification is selected from the available network slice specifications and wherein a request of the first network slice specification is sent to the cloud-slice management API via a data link by using the slice-connectivity manager, wherein the cloud-slice management API forwards the request to a slice-service-orchestration module of the connectivity-management entity, wherein the slice-service-orchestration module provides a first communication interface to the network of a network operator, wherein the slice-service-orchestration module sends signals to the network so that the network starts a set-up process of the first network slice with the first specification.