Network Slice Isolation Management via Segmented Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack a central and unified management/orchestration solution for isolating resources of Network Slices across multiple domains with different isolation levels, compromising network security and service assurance.

Innovation Solution

The method involves creating and managing isolation groups for network services, where resources are shared with or without isolation, and linking isolation profiles to define protection policies and isolation levels, ensuring resource allocation is based on these profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If resources are shared across multiple domains without isolation, then resource utilization efficiency is improved, but network security and service assurance deteriorate

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidnetwork security and service assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments resources into isolation groups with different isolation levels (first isolation level for high security, second isolation level for standard security). This allows resources to be shared across domains while maintaining security through hierarchical segmentation, resolving the contradiction between efficiency and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different isolation levels are applied to different resource groups based on their security requirements. High-security resources receive first isolation level protection while standard resources receive second isolation level, enabling differentiated security that maintains both efficiency and security where needed.

Inventive Principle:
Principle #3Local quality

2Reliability

If isolation levels are implemented for resource protection, then network security is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management system is segmented into functional modules: isolation group management, isolation level assignment, and resource allocation. This modular segmentation reduces overall system complexity by dividing the management overhead into manageable, independent functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Isolation groups and their associated isolation levels are pre-configured and linked before resource allocation. This preliminary setup eliminates the need for complex real-time isolation configuration, reducing management overhead during resource deployment while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized isolation management is implemented, then service assurance is improved, but system complexity increases

Engineering Contradiction:
Improveservice assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The isolation groups and isolation levels are designed as universal constructs that can be applied across multiple domains (access network, core network, transport network). This multi-functionality allows centralized management to provide consistent service assurance across the entire network without requiring domain-specific complex management systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Isolation groups act as intermediaries between the centralized management system and individual network resources. They abstract the complexity of multi-domain isolation into a unified management interface, allowing centralized control without exposing the underlying complexity to the management system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12245042B2Method for network slice isolation management
Publication Date: 2025.03.04 NOKIA TECHNOLOGIES OY
  • US12245042B2 patent drawing
  • US12245042B2 patent drawing
  • US12245042B2 patent drawing

AI summary

A method for network isolation management is described. The method includes assigning or creating one or more isolation groups for at least one service, wherein resources of services assigned in an isolation group are shared with or without isolation; wherein an isolation group is defined for at least one resource in each layer and each domain to gather the at least one resource of the at least one service; linking an isolation profile for each of the one or more isolation groups, wherein the isolation profile comprises at least one policy to protect the at least one resource of the one or more isolation groups, and wherein the isolation profile comprises at least an isolation level to define a type of isolation; and allocating or reallocating the at least one resource to the at least one service based on the isolation profile linked to the one or more isolation groups.