Control Device for Virtual Network Function Isolation in IoT Edge Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IoT network systems, there is a need to manage and isolate data transmission networks deployed by different carriers, as they often handle sensitive data, requiring efficient network separation and management without the need for dedicated edge nodes, which poses challenges in installation space and security management, especially in competitive environments.
Innovation Solution
A network system and method that builds virtual network functions for each service, allowing data from multiple data transmission nodes to be transmitted through a control apparatus, enabling separate handling of data from different carriers by creating virtual networks for each service, using techniques like tunneling and logical slicing, and employing a controller to manage edge nodes and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated edge nodes are deployed for each carrier to handle sensitive data, then data security and network isolation are improved, but installation space requirements and security management complexity increase
Solution Approach 1:
The patent merges multiple carriers' edge nodes into a single shared edge node infrastructure. The control device consolidates authentication and data transmission management for multiple carriers, eliminating the need for separate dedicated edge nodes while maintaining security isolation through virtual network functions and authentication-based data separation.
Solution Approach 2:
The shared edge node is designed with universal functionality to handle data transmission for multiple carriers simultaneously. The control device provides multi-functional authentication and data routing capabilities, enabling a single edge node to serve multiple carriers with different security requirements through logical separation rather than physical segregation.
2Reliability
If multiple dedicated edge nodes are deployed for different carriers, then network isolation for sensitive data is improved, but installation space requirements increase
Solution Approach 1:
The patent combines multiple carrier-specific edge node functions into a single shared edge node. The control device implements logical network isolation through authentication mechanisms and virtual network functions, achieving the same security isolation effect as multiple dedicated nodes without requiring multiple physical installations.
Solution Approach 2:
The patent transitions from physical dimension separation (multiple dedicated edge nodes) to logical dimension separation (virtual network functions and authentication-based data separation). This dimensional shift allows network isolation to be achieved through software-based virtualization rather than physical infrastructure multiplication.
3Reliability
If separate edge nodes are used for each carrier, then data management and isolation are improved, but cost and security management burden increase
Solution Approach 1:
The patent merges security management functions into a centralized control device that handles authentication and data routing for multiple carriers. This consolidation reduces the security management burden by providing unified policy enforcement and centralized control, while maintaining carrier-specific data isolation through authentication-based separation.
Solution Approach 2:
The control device acts as an intermediary between multiple carriers and the shared edge node. It mediates authentication requests, data transmission routing, and security policy enforcement, simplifying security management by providing a single point of control rather than requiring each carrier to manage their own dedicated edge node security independently.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention resolves various problems faced by networks in which plural data transmitting entities are deployed. The network system includes: a first physical network that includes a first data transmission node that transmits data used in a first service and a second data transmission node that transmits data used in a second service; a second physical network that includes one or a plurality of apparatuses for receiving data from the first and/or second data transmission nodes; and a control apparatus, in the first physical network, for building a virtual network function for transmitting data received from the first and second data transmission nodes directed to the second physical network.