Commissioning Virtualized Network Functions via Intermediary VM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The commissioning of virtualized network functions (VNFs) in customer networks is inefficient and prone to errors due to customer-managed instantiation and configuration of virtual machines (VMs), leading to potential misconfigurations and security risks.
Innovation Solution
A method and apparatus for commissioning a VNF that involves instantiating a commissioning VM with a remote access connection facility, allowing a remote engineer to configure and manage the VNF manager component, which instructs the virtual infrastructure manager to instantiate and configure other VMs, thereby reducing customer involvement and enhancing security by providing a controlled single point of access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If customers manually instantiate and configure VMs to perform VNF, then customers have control over the process, but errors and misconfigurations occur reducing reliability
Solution Approach 1:
A commissioning VM is introduced as an intermediary between the customer network and the VNF deployment process. This commissioning VM provides a controlled entry point that engineers can access remotely to configure the VNF environment, eliminating the need for customers to directly instantiate and configure multiple VMs while maintaining system control and reducing errors.
Solution Approach 2:
The system enables self-service through automated configuration processes. Once the commissioning VM is in place, engineers can remotely configure the VNF manager component, which then automatically instructs the VIM to instantiate and configure the necessary VMs, reducing manual customer involvement and potential for human error.
2Ease of operation
If engineers are granted access to customer network via VPN server on VMs, then configuration can be performed remotely, but security risks increase due to multiple access points
Solution Approach 1:
The access architecture is segmented into a dedicated commissioning VM that serves as a isolated entry point. This commissioning VM is specifically designed for commissioning activities and can be securely accessed by engineers, while the rest of the customer network remains protected. The commissioning VM acts as a containment zone that limits potential security breaches to a single isolated instance.
Solution Approach 2:
The commissioning VM serves as a secure intermediary that mediates between external engineers and the internal customer network. All remote access connections are routed through this single controlled point, allowing engineers to configure the VNF environment without directly accessing the customer's production systems, thereby minimizing security exposure.
3Productivity
If multiple VMs are instantiated by customers to perform VNF, then full functionality is achieved, but the process becomes complex and time-consuming
Solution Approach 1:
The commissioning VM is prepared in advance with the necessary configuration tools and access facilities before being deployed to the customer network. This preliminary preparation includes setting up the remote access connection facility and VNF manager component, so that once deployed, the actual VNF instantiation can proceed quickly through automated processes rather than requiring customers to manually configure each VM from scratch.
Solution Approach 2:
The VNF manager component, once configured through the commissioning VM, automatically performs the instantiation and configuration of the required VMs through the VIM. This self-service capability eliminates the need for customers to manually instantiate each VM and configure it individually, significantly reducing both the time and complexity of the commissioning process.
Data Source
AI summary
Certain aspects provide a method of commissioning a virtualized network function (VNF), including: at a commissioning virtual machine instantiated in a virtualized environment of a customer network, configuring a remote access connection facility for accessing the commissioning virtual machine remotely from outside of the customer network, wherein the commissioning virtual machine has access to a virtual infrastructure manager (VIM) component of the virtualized environment; causing, via the remote access connection facility, configuration of a VNF manager component within the commissioning virtual machine; and causing, via the remote access connection facility, the configured VNF manager component to instruct the VIM component to instantiate one or more virtual machines in the virtualized environment, the one or more virtual machines being operable to perform at least a part of the VNF.


