Virtual Network Functions for Carrier Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT network systems, there is a need to isolate networks deployed by different carriers due to competitive relationships and confidentiality concerns, which poses challenges in installation space and security management, especially when multiple edge nodes are deployed in limited areas like homes or offices.

Innovation Solution

A network system that configures virtual network functions between physical networks, allowing data from different services to be transmitted securely by using tunneling and logical slicing, with a controller managing data forwarding paths and processing rules, enabling separate virtual networks for each carrier without the need for dedicated edge gateways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple dedicated edge gateways are deployed for each carrier, then network isolation and security are improved, but installation space requirements and device complexity increase

Engineering Contradiction:
Improvenetwork isolationVSAvoidedge gateway deployment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple carrier networks into a single shared physical infrastructure by deploying one common edge gateway that hosts multiple virtual network functions. This consolidation maintains network isolation through virtualization while eliminating the need for separate physical gateways for each carrier, thereby reducing installation space and device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The edge gateway is designed with multi-functionality to serve multiple carriers simultaneously. By implementing virtual network function modules that can be dynamically configured, a single gateway performs the functions of multiple dedicated gateways, achieving carrier isolation without requiring separate hardware installations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple dedicated edge gateways are deployed for each carrier, then network security management is improved, but installation space and cost increase

Engineering Contradiction:
Improvesecurity managementVSAvoidinstallation space
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

Multiple carrier networks are merged into a single shared physical infrastructure with one common edge gateway. Security management is maintained through virtualization-based isolation mechanisms that logically separate carrier traffic while physically consolidating infrastructure, thereby reducing installation space requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Instead of deploying separate physical gateways, the system creates virtual copies of gateway functions through software-based virtual network functions. These virtual instances provide the same security management capabilities as physical gateways but occupy minimal physical space.

Inventive Principle:
Principle #26Copying

3Reliability

If separate physical networks are used for each carrier, then network isolation is improved, but resource utilization and cost efficiency deteriorate

Engineering Contradiction:
Improvenetwork isolationVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges separate carrier networks into a shared physical infrastructure while maintaining logical isolation through virtualization. This approach improves resource utilization by allowing multiple carriers to share the same physical resources (gateway, network interface, processing power) while still maintaining network isolation through virtual network functions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system transitions from physical network isolation to virtual network isolation by adding a virtualization layer. This dimensional shift allows networks to be isolated at the software/virtualization level rather than requiring separate physical infrastructure, thereby improving resource utilization while maintaining isolation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If dedicated edge nodes are deployed for each carrier, then network security is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidedge node management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple carrier edge nodes are merged into a single multi-functional edge gateway. Network security is maintained through virtualization-based isolation that separates carrier traffic and access control, while management overhead is reduced by consolidating configuration, monitoring, and maintenance tasks into a single unified system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The edge gateway is designed as a universal platform that can serve multiple carriers with different service requirements. It implements configurable virtual network functions that provide carrier-specific security and isolation while being managed through a unified interface, thereby reducing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3425853B1Network system, terminal, sensor data collection method, and program
Publication Date: 2023.09.20 NEC CORP
  • EP3425853B1 patent drawingFigure 1
  • EP3425853B1 patent drawingFigure 2
  • EP3425853B1 patent drawingFigure 3

AI summary

The invention resolves various problems faced by networks in which plural data transmitting entities are deployed. A network system comprises: a terminal(s) that is connectable to a sensor(s), converts data collected by the sensor(s) into second data by performing predetermined processing on the collected data, and transmits the second data to the predetermined apparatus(es) arranged in a physical network(s); the physical network(s) that includes the predetermined apparatus(es); and a control apparatus that controls a virtual network(s) established between the terminal(s) and the predetermined apparatus(es) so that the second data transmitted from the terminal(s) reaches the predetermined apparatus(es).