RAN Node SLA Verification for Network Slice Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication networks face challenges in managing connection requests for network slices efficiently, particularly in ensuring that resources allocated correspond to Service Level Agreements (SLAs), which is crucial for maintaining network integrity and security, especially with the introduction of network slicing in 5G networks where different operators may manage and run core and radio access networks independently.

Innovation Solution

Implementing a method within Radio Access Network (RAN) and Core Network (CN) nodes to supervise and police the allocation of resources for network slices by using a Service Level Agreement (SLA) database to verify if requested resources match the agreed SLA, and if not, adapting or rejecting the requests to ensure compliance, thereby preventing potential attacks or overloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network slicing is implemented to allow different operators to manage core and radio access networks independently, then network flexibility and adaptability are improved, but network security and integrity are worsened due to potential non-compliant resource allocations

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements a feedback mechanism where the RAN node receives resource allocation information from the CN node, verifies it against stored SLA parameters, and provides feedback by rejecting non-compliant allocations. This continuous verification loop ensures that network slicing maintains both flexibility and security by actively monitoring and enforcing SLA compliance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The RAN node performs preliminary verification of resource allocation requests against pre-stored SLA parameters before actually allocating resources. This preliminary action prevents non-compliant allocations from being executed, thereby maintaining network security while allowing flexible network slicing operations to proceed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If resource allocation verification is performed for each network slice request, then network security is improved, but processing time and complexity are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The SLA parameters are stored in advance in the RAN node's memory before resource allocation requests arrive. This preliminary preparation eliminates the need for real-time complex calculations, allowing the RAN node to quickly compare requested resources against pre-stored SLA parameters and make rapid verification decisions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a simplified verification model by storing key SLA parameters as reference copies in the RAN node. Instead of performing complex real-time verification calculations, the RAN node compares requested resources against these pre-fetched parameter copies, significantly reducing processing time while maintaining security.

Inventive Principle:
Principle #26Copying

3Reliability

If strict SLA compliance is enforced for network slices, then network integrity is improved, but connection request rejection increases

Engineering Contradiction:
Improvenetwork integrityVSAvoidconnection success rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system provides feedback to the CN node when resource allocations do not meet SLA requirements, enabling the CN node to adjust its requests. This feedback mechanism ensures network integrity by rejecting only truly non-compliant requests while allowing flexible adjustments that maintain both integrity and connection success rate.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The verification process is designed to be dynamic rather than rigid, allowing the system to adapt to different network conditions and SLA interpretations. The RAN node can flexibly evaluate resource requests against SLA parameters and provide nuanced feedback, enabling both strict integrity enforcement and connection success.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11323335B2SLA handling in network slices
Publication Date: 2022.05.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11323335B2 patent drawing
  • US11323335B2 patent drawing
  • US11323335B2 patent drawing

AI summary

Embodiments herein relate to a method performed by a RAN node (12), for managing communication on a first network slice in a communications network (1). The communications network (1) comprises partitioned sets of functionalities. A first set of functionalities belongs to the first network slice. The first set of functionalities is at least 5 partly separated from another set of functionalities out of a total set of functionalities in the communications network (1). The RAN node (12) receives, from a CN node (16), information regarding requested resources for a first network slice identified by a network slice identifier. The RAN node (12) determines that the received information does not correspond to a Service Level Agreement (SLA) for the first network slice.