Edge Cloud Proxy Pair for Seamless Network Function Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication networks face inefficiencies and security issues when establishing communication between network functions deployed in on-premises and cloud networks, particularly due to the need for cumbersome tunnel establishment and reconfiguration of firewall and security policies, which can lead to security vulnerabilities.
Innovation Solution
Implementing a pair of proxy services, namely edge proxy and cloud proxy, that utilize a pull-pull API over HTTP to route data between edge and cloud network functions, eliminating the need for tunnel establishment and minimizing security risks by maintaining secure communication without exposing API endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If tunnel establishment is used to connect edge and cloud network functions, then connectivity is provided, but security vulnerabilities and configuration complexity increase
Solution Approach 1:
The patent introduces a network proxy as an intermediary component deployed at the network edge that mediates communication between edge network functions and cloud network functions. The proxy receives requests from edge functions, forwards them to the cloud, and relays responses back, eliminating the need for direct tunnel connections while maintaining secure communication through standardized HTTP protocols and existing firewall rules
2Reliability
If tunnel establishment is used to connect edge and cloud network functions, then connectivity is provided, but configuration complexity increases
Solution Approach 1:
The network proxy acts as a simplifying intermediary that handles all complex configuration requirements centrally. It provides automated service discovery, dynamic routing, and request forwarding capabilities that eliminate the need for manual tunnel configuration, firewall rule updates, and endpoint registration across the network
Solution Approach 2:
The patent implements a pull-based API mechanism where the network proxy maintains a copy or representation of service endpoints and uses HTTP requests to discover and communicate with cloud network functions. This copying approach simplifies configuration by allowing the proxy to dynamically update its service registry without requiring complex real-time synchronization protocols
3Ease of operation
If API endpoints are exposed for direct communication, then connectivity is improved, but security risks increase
Solution Approach 1:
The network proxy serves as a security intermediary that sits between edge network functions and cloud network function API endpoints. It receives and validates all requests, performs authentication and authorization checks, and forwards only legitimate requests to the cloud, thereby enabling easy connectivity while maintaining security without requiring API endpoint exposure
Solution Approach 2:
The system implements self-service security mechanisms where the network proxy automatically performs service discovery, validates request authenticity, and manages communication security policies without manual intervention. This self-service approach maintains security while simplifying operations by eliminating the need for manual API endpoint exposure and configuration
Data Source
AI summary
Methods are provided for a first proxy service obtaining a request originating from a source network function for a destination network function. These functions are each one of a cloud network function deployed in a cloud network and an edge network function deployed in an on-premises network. The methods further involve providing the request to the destination network function when the request is received from a second proxy service or to the second proxy service when the request is received from the source network function such that the second proxy service provides the request to the destination network function. The first proxy service and the second proxy service are each one of a cloud proxy service deployed in the cloud and configured to communicate with the cloud network function and an edge proxy service deployed at the edge and configured to communicate with the edge network function.


