CPE Slicing for Multi-Manager Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for managing consumer premises equipment (CPE) devices allow a primary network manager to have complete access to communications with third-party network managers, leading to computing overhead and lack of privacy, as well as inadequate isolation of resources for multiple service providers using the same CPE.
Innovation Solution
Implementing a system where a root network manager provisions slices of CPE resources, allowing secondary network managers to directly manage their corresponding slices without relying on the primary entity, using protocols like CWMP and SNMP for communication, and utilizing virtual machines for isolation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a primary network manager manages all communications with third-party network managers, then complete access and control is achieved, but computing overhead increases and privacy is compromised
Solution Approach 1:
The CPE device is divided into multiple isolated slices, each managed by a specific network manager. The first slice is managed by the primary network manager while the second slice is managed by the third-party network manager. This segmentation allows each manager to control only their designated slice, reducing the computing overhead for the primary network manager while maintaining reliable control over their respective portions.
Solution Approach 2:
The CPE device acts as an intermediary between the primary network manager and the third-party network manager. It receives management communications from both parties and routes them to the appropriate slices. This intermediary role enables the primary network manager to maintain control over the overall device while the third-party network manager can privately manage their slice without direct involvement of the primary manager in all communications.
2Reliability
If a primary network manager has complete access to all communications, then full control is maintained, but privacy for third-party service providers is compromised
Solution Approach 1:
The CPE device is divided into multiple isolated slices, each managed by a specific network manager. The first slice is managed by the primary network manager while the second slice is managed by the third-party network manager. This segmentation allows each manager to control only their designated slice, reducing the computing overhead for the primary network manager while maintaining reliable control over their respective portions.
Solution Approach 2:
Different slices of the CPE device have different management access rights. The first slice is configured to accept management communications only from the primary network manager, while the second slice is configured to accept management communications only from the third-party network manager. This local quality differentiation ensures that each manager has full control over their designated slice while maintaining privacy from other managers.
3Productivity
If CPE resources are shared among multiple service providers, then resource efficiency improves, but resource isolation and security are compromised
Solution Approach 1:
The CPE device is divided into multiple isolated slices, each dedicated to a specific service provider or tenant. This segmentation allows multiple service providers to share the physical CPE resources while maintaining logical isolation between their respective workloads, thereby achieving both resource efficiency and security.
Solution Approach 2:
Different slices of the CPE device have different management access rights. The first slice is configured to accept management communications only from the primary network manager, while the second slice is configured to accept management communications only from the third-party network manager. This local quality differentiation ensures that each manager has full control over their designated slice while maintaining privacy from other managers.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
At a customer premises equipment comprising one or more network interfaces, an instruction to provision a slice of the customer premises equipment (CPE) for a tenant application is received from a root network manager. The instruction identifies at least one network interface of the one or more network interfaces to allocate to the slice. The slice of the CPE is provisioned, where provisioning the slice comprises allocating CPE resources including the at least one network interface to the slice of the customer premises equipment. The tenant application is obtained. Data associating the tenant application with the slice of the CPE is stored. A management instruction for managing the tenant application is received directly from a secondary network manager associated with the tenant application. The management instruction is executed only in relation to the slice.