Control Device for Virtual Network Function Isolation in IoT Edge Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT network systems, there is a need to manage and isolate data transmission networks deployed by different carriers, as they often handle sensitive data, requiring efficient network separation and management without the need for dedicated edge nodes, which poses challenges in installation space and security management, especially in competitive environments.

Innovation Solution

A network system and method that builds virtual network functions for each service, allowing data from multiple data transmission nodes to be transmitted through a control apparatus, enabling separate handling of data from different carriers by creating virtual networks for each service, using techniques like tunneling and logical slicing, and employing a controller to manage edge nodes and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated edge nodes are deployed for each carrier to handle sensitive data, then data security and network isolation are improved, but installation space requirements and security management complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple carriers' edge nodes into a single shared edge node infrastructure. The control device consolidates authentication and data transmission management for multiple carriers, eliminating the need for separate dedicated edge nodes while maintaining security isolation through virtual network functions and authentication-based data separation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared edge node is designed with universal functionality to handle data transmission for multiple carriers simultaneously. The control device provides multi-functional authentication and data routing capabilities, enabling a single edge node to serve multiple carriers with different security requirements through logical separation rather than physical segregation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple dedicated edge nodes are deployed for different carriers, then network isolation for sensitive data is improved, but installation space requirements increase

Engineering Contradiction:
Improvenetwork isolationVSAvoidinstallation space
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent combines multiple carrier-specific edge node functions into a single shared edge node. The control device implements logical network isolation through authentication mechanisms and virtual network functions, achieving the same security isolation effect as multiple dedicated nodes without requiring multiple physical installations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent transitions from physical dimension separation (multiple dedicated edge nodes) to logical dimension separation (virtual network functions and authentication-based data separation). This dimensional shift allows network isolation to be achieved through software-based virtualization rather than physical infrastructure multiplication.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If separate edge nodes are used for each carrier, then data management and isolation are improved, but cost and security management burden increase

Engineering Contradiction:
Improvedata managementVSAvoidsecurity management burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security management functions into a centralized control device that handles authentication and data routing for multiple carriers. This consolidation reduces the security management burden by providing unified policy enforcement and centralized control, while maintaining carrier-specific data isolation through authentication-based separation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The control device acts as an intermediary between multiple carriers and the shared edge node. It mediates authentication requests, data transmission routing, and security policy enforcement, simplifying security management by providing a single point of control rather than requiring each carrier to manage their own dedicated edge node security independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3425855B1Network system, control device, method and program for building virtual network function
Publication Date: 2020.04.22 NEC CORP
  • EP3425855B1 patent drawingFigure 1
  • EP3425855B1 patent drawingFigure 2
  • EP3425855B1 patent drawingFigure 3

AI summary

The invention resolves various problems faced by networks in which plural data transmitting entities are deployed. The network system includes: a first physical network that includes a first data transmission node that transmits data used in a first service and a second data transmission node that transmits data used in a second service; a second physical network that includes one or a plurality of apparatuses for receiving data from the first and/or second data transmission nodes; and a control apparatus, in the first physical network, for building a virtual network function for transmitting data received from the first and second data transmission nodes directed to the second physical network.