Container Manager Isolating Applications Across Network Slices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems lack mechanisms to clearly separate applications serving different business purposes on a device and associate them with specific network slices, leading to security concerns and inadequate isolation of resources.
Innovation Solution
Implementing a container environment with a container manager that associates each container with a unique network slice, preventing communication between applications in different containers, and using dedicated or encrypted access methods to ensure secure and isolated operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If applications are allowed to communicate freely across the device, then ease of operation is improved, but security is worsened due to malware spread risks
Solution Approach 1:
The patent divides the device into multiple isolated containers, each hosting applications that require separation. This segmentation prevents malware in one container from spreading to other containers while maintaining ease of operation within each container. The container manager enforces these boundaries to ensure security without compromising operational freedom within isolated contexts.
2Productivity
If multiple applications share network resources, then productivity is improved, but reliability is worsened due to inadequate resource isolation
Solution Approach 1:
The patent segments network resource access by associating each container with specific network slices. This allows multiple applications to share network resources efficiently while maintaining reliable isolation through the container manager, which controls and monitors resource allocation to prevent interference between containers.
Solution Approach 2:
The container manager acts as an intermediary between applications and network resources. It mediates resource allocation by controlling communication between containers and network slices, ensuring that applications can share resources productively while maintaining reliable isolation through centralized management and monitoring.
3Device complexity
If network resources are virtualized and shared, then device complexity is reduced, but measurement precision is worsened in tracking resource usage
Solution Approach 1:
The container manager implements feedback mechanisms to track resource usage across virtualized networks. It monitors and records resource consumption by each container, providing precise measurement data despite the virtualization layer. This feedback enables accurate tracking of network slice usage, container resource allocation, and application performance metrics.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A communication device (405) comprises a container environment with a plurality of containers (FIG. 4, containers 1-x) each having one or more applications (FIG. 4, APP 1.1- x.p) and each being connectable to a network slice (FIG. 4, slices 1-x), and a container manager (FIG. 4, container manager) configured to control communication between the applications and the network slices, wherein the container manager prohibits communication between a first application in a first container and a second application in a second container.