RAN Node SLA Verification for Network Slice Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication networks face challenges in managing connection requests for network slices efficiently, particularly in ensuring that resources allocated correspond to Service Level Agreements (SLAs), which is crucial for maintaining network integrity and security, especially with the introduction of network slicing in 5G networks where different operators may manage and run core and radio access networks independently.
Innovation Solution
Implementing a method within Radio Access Network (RAN) and Core Network (CN) nodes to supervise and police the allocation of resources for network slices by using a Service Level Agreement (SLA) database to verify if requested resources match the agreed SLA, and if not, adapting or rejecting the requests to ensure compliance, thereby preventing potential attacks or overloads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network slicing is implemented to allow different operators to manage core and radio access networks independently, then network flexibility and adaptability are improved, but network security and integrity are worsened due to potential non-compliant resource allocations
Solution Approach 1:
The system implements a feedback mechanism where the RAN node receives resource allocation information from the CN node, verifies it against stored SLA parameters, and provides feedback by rejecting non-compliant allocations. This continuous verification loop ensures that network slicing maintains both flexibility and security by actively monitoring and enforcing SLA compliance.
Solution Approach 2:
The RAN node performs preliminary verification of resource allocation requests against pre-stored SLA parameters before actually allocating resources. This preliminary action prevents non-compliant allocations from being executed, thereby maintaining network security while allowing flexible network slicing operations to proceed.
2Reliability
If resource allocation verification is performed for each network slice request, then network security is improved, but processing time and complexity are worsened
Solution Approach 1:
The SLA parameters are stored in advance in the RAN node's memory before resource allocation requests arrive. This preliminary preparation eliminates the need for real-time complex calculations, allowing the RAN node to quickly compare requested resources against pre-stored SLA parameters and make rapid verification decisions.
Solution Approach 2:
The system creates a simplified verification model by storing key SLA parameters as reference copies in the RAN node. Instead of performing complex real-time verification calculations, the RAN node compares requested resources against these pre-fetched parameter copies, significantly reducing processing time while maintaining security.
3Reliability
If strict SLA compliance is enforced for network slices, then network integrity is improved, but connection request rejection increases
Solution Approach 1:
The system provides feedback to the CN node when resource allocations do not meet SLA requirements, enabling the CN node to adjust its requests. This feedback mechanism ensures network integrity by rejecting only truly non-compliant requests while allowing flexible adjustments that maintain both integrity and connection success rate.
Solution Approach 2:
The verification process is designed to be dynamic rather than rigid, allowing the system to adapt to different network conditions and SLA interpretations. The RAN node can flexibly evaluate resource requests against SLA parameters and provide nuanced feedback, enabling both strict integrity enforcement and connection success.
Data Source
AI summary
Embodiments herein relate to a method performed by a RAN node (12), for managing communication on a first network slice in a communications network (1). The communications network (1) comprises partitioned sets of functionalities. A first set of functionalities belongs to the first network slice. The first set of functionalities is at least 5 partly separated from another set of functionalities out of a total set of functionalities in the communications network (1). The RAN node (12) receives, from a CN node (16), information regarding requested resources for a first network slice identified by a network slice identifier. The RAN node (12) determines that the received information does not correspond to a Service Level Agreement (SLA) for the first network slice.


