Virtual Network Functions for IoT Carrier Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IoT network systems, there is a need to isolate networks deployed by different carriers due to competitive relationships and the sensitivity of data, such as personal information and company secrets, while also facing challenges with installation space and cost in homes and offices for edge node management.
Innovation Solution
A network system that configures virtual network functions between physical networks, allowing data from different services to be transmitted securely by using tunneling and logical slicing, with a controller managing data forwarding paths and processing rules, and employing network function virtualization to create virtual network functions without dedicated IoT gateways.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated IoT gateways are deployed for each carrier, then network isolation and security are improved, but installation space requirements and device complexity increase
Solution Approach 1:
Multiple carriers share a single physical IoT gateway infrastructure. The gateway is virtualized to provide logical isolation while physically consolidating resources, eliminating the need for separate dedicated gateways for each carrier and reducing installation space requirements.
Solution Approach 2:
The single shared gateway is segmented into multiple virtual network instances, each dedicated to a specific carrier. This segmentation provides logical isolation and security boundaries while maintaining physical consolidation, resolving the contradiction between isolation requirements and device complexity.
2Reliability
If dedicated IoT gateways are deployed for each carrier, then data security and isolation are improved, but installation cost and space requirements increase
Solution Approach 1:
Multiple carriers share a single physical IoT gateway infrastructure through virtualization. This consolidation reduces the total quantity of hardware devices required, lowering installation costs while maintaining data security through logical isolation mechanisms.
Solution Approach 2:
Instead of deploying physical copies of gateways for each carrier, virtual copies are created through software-defined network instances. This allows multiple carriers to have dedicated logical gateways without the cost of physical hardware multiplication.
3Device complexity
If virtual network functions are shared, then device complexity is reduced, but network isolation and security may be compromised
Solution Approach 1:
The shared physical gateway is segmented into multiple isolated virtual network instances, each dedicated to a specific carrier. This segmentation maintains network isolation and security boundaries while enabling resource sharing, resolving the contradiction between device complexity reduction and reliability maintenance.
Solution Approach 2:
A virtualization layer acts as an intermediary between the shared physical infrastructure and individual carrier networks. This intermediary provides logical isolation and security enforcement while enabling efficient resource sharing, preventing direct interference between carrier networks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention resolves various problems faced by networks in which plural data transmitting entities are deployed. A network system is connected to a first physical network comprising: a first data transmission node that transmits data used for a first service and a second data transmission node that transmits data used for a second service and to a second physical network including at least one apparatus for receiving data from the first and the second data transmission nodes, and constructs a virtual network for each service between the first and the second physical networks.