Cloud Slice Connectivity Manager for Automated Network Slicing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of connectivity between mobile apps and services and cloud environments is complex and lacks automation, leading to security concerns and inefficiencies, especially with the rollout of 5G network slicing.

Innovation Solution

A slice-connectivity manager is implemented as a virtual software within a customer's Virtual Private Cloud (VPC) in the cloud provider's cloud, which connects to a cloud-slice management API. This manager allows customers to authenticate, order, modify, and terminate Network as a Service (NaaS) products without sharing customer cloud account credentials, enhancing security and simplifying administration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple administration points (cloud provider, network operator, MDM) are used to manage connectivity, then comprehensive service management is achieved, but system complexity and difficulty of ensuring consistency increase

Engineering Contradiction:
Improveservice management capabilityVSAvoidadministration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based network slice management system as an intermediary layer between the cloud provider, network operator, and MDM. This system provides unified APIs and automated workflows that coordinate actions across all administration points, reducing complexity while maintaining comprehensive service management capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management system is designed to perform multiple functions across different administration domains through a single unified interface. It can manage network slice provisioning, configuration, monitoring, and termination across cloud, network, and device layers, eliminating the need for separate administration points

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If manual configuration and direction are required for VPN setup, then security can be controlled, but automation and speed are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidsetup automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system enables automated self-service VPN configuration where the cloud-based management system automatically provisions network slices, configures VPN tunnels, and coordinates with MDM devices without requiring manual intervention. Security policies are pre-defined and automatically applied, maintaining security control while achieving full automation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security policies, VPN configurations, and network slice parameters are pre-configured and validated before deployment. The system performs preliminary security checks and automatically applies approved configurations, ensuring security requirements are met while enabling rapid automated setup

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If customer cloud account credentials are shared with network provider, then service integration is simplified, but security level is reduced

Engineering Contradiction:
Improveservice integrationVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cloud-based management system as a secure intermediary that handles all authentication and credential management. Customer credentials never leave the customer's cloud account, while the management system uses secure token-based authentication and API key mechanisms to enable service integration without credential sharing

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments authentication and authorization functions into separate secure modules. Different levels of access are provided through role-based access control (RBAC), where the management system receives limited, specific permissions rather than full customer credentials, maintaining security while enabling integration

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If VPN secrets (usernames, passwords) are exchanged between parties, then connection can be established, but security risk and manual effort increase

Engineering Contradiction:
Improveconnection establishmentVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system replaces manual exchange of VPN secrets with automated cryptographic key management. Public key infrastructure (PKI) and certificate-based authentication are used instead of traditional username/password mechanisms. Secrets are generated, exchanged, and managed automatically through secure APIs, eliminating manual handling while establishing connections

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4498650A1Techniques to set up network as a service into cloud environments
Publication Date: 2025.01.29 DEUTSCHE TELEKOM AG
  • EP4498650A1 patent drawingFigure 1
  • EP4498650A1 patent drawingFigure 2
  • EP4498650A1 patent drawingFigure 3

AI summary

A method and system for setting up a network slice in a network between a UE and a VPC of a customer within the cloud of a cloud provider comprising the following steps: Providing a slice-connectivity manager and a connectivity-management entity, wherein a cloud-slice management API of the connectivity-management entity offers available network slice specifications of the network to the slice-connectivity manager, wherein a first network slice specification is selected from the available network slice specifications and wherein a request of the first network slice specification is sent to the cloud-slice management API via a data link by using the slice-connectivity manager, wherein the cloud-slice management API forwards the request to a slice-service-orchestration module of the connectivity-management entity, wherein the slice-service-orchestration module provides a first communication interface to the network of a network operator, wherein the slice-service-orchestration module sends signals to the network so that the network starts a set-up process of the first network slice with the first specification.