NFV Borderline Gateway for Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In NFV-based networks, there is a need to limit the impact of internal network entities on the communication network to prevent adverse effects such as increased latency, jitter, and resource consumption, while ensuring secure and efficient communication between internal and external entities.

Innovation Solution

A system and method that utilize a container with a borderline gateway to isolate internal network entities, such as virtual network functions (VNFs), and assign protective limits to the gateway to control interactions with external entities, allowing only controlled communication through the gateway, which can automatically adjust limits based on load and consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If internal network entities are allowed to communicate freely with external entities, then communication efficiency is improved, but network security and stability deteriorate due to potential adverse effects

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidnetwork stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The network is segmented into internal entities and external entities with a borderline gateway as the boundary. This segmentation allows free communication within segments while controlling inter-segment communication, thus maintaining efficiency within segments and stability across the entire network through isolated boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The borderline gateway acts as an intermediary between internal and external network entities. It mediates all communications crossing the boundary, enabling efficient communication while enforcing protective limits to prevent adverse effects, thereby maintaining both communication efficiency and network stability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If protective limits are imposed on internal network entities, then network security is improved, but communication flexibility deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The protective limits at the borderline gateway are designed to be dynamic rather than static. The gateway can adjust limits based on current network conditions, load, and consumption patterns, thereby maintaining security while adapting to changing communication needs and preserving flexibility.

Inventive Principle:
Principle #15Dynamics

3Productivity

If multiple VNFs from different vendors are managed in a single NFV-O, then resource utilization is improved, but system complexity and security risk increase

Engineering Contradiction:
Improveresource utilizationVSAvoidmanagement complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The management system is segmented into container-level management for individual VNFs and NFV-O level orchestration. Each container manages its internal VNFs independently, reducing management complexity, while the NFV-O coordinates across containers to maintain efficient resource utilization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The container acts as an intermediary layer between individual VNFs and the NFV-O. It simplifies the interface for VNF management while maintaining resource coordination capabilities, thereby reducing management complexity without sacrificing resource utilization efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If internal network entities are isolated using containers, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidcontainer management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The container is designed as a universal management unit that handles multiple functions: isolation of VNFs, enforcement of protective limits, resource management, and coordination with NFV-O. This multi-functionality reduces the need for separate mechanisms, thereby improving security without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9667509B1System, method, and computer program for secluding a service in a network based on network function virtualization (NFV)
Publication Date: 2017.05.30 AMDOCS DEV LTD
  • US9667509B1 patent drawing
  • US9667509B1 patent drawing
  • US9667509B1 patent drawing

AI summary

A system, method, and computer program product are provided for limiting an impact of at least one internal network entity on a network function virtualization (NFV) based communication network hosting the network entity, the method including: providing a container including at least one borderline gateway, providing within the container at least one of internal network entity, where the internal network entity includes a software module, a virtual network function (VNF), and a VNF instance, and assigning the borderline gateway at least one protective limit, where NFV-based network includes at least one external network entity, the external network entity is external to the container, where the at least one internal network entity communicates with any of the external network entities only via the at least one borderline gateway, and where the borderline gateway is operative to use the protective limit to limit the impact on the NFV-based network.