Virtual Network Functions for IoT Carrier Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT network systems, there is a need to isolate networks deployed by different carriers due to competitive relationships and the sensitivity of data, such as personal information and company secrets, while also facing challenges with installation space and cost in homes and offices for edge node management.

Innovation Solution

A network system that configures virtual network functions between physical networks, allowing data from different services to be transmitted securely by using tunneling and logical slicing, with a controller managing data forwarding paths and processing rules, and employing network function virtualization to create virtual network functions without dedicated IoT gateways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated IoT gateways are deployed for each carrier, then network isolation and security are improved, but installation space requirements and device complexity increase

Engineering Contradiction:
Improvenetwork isolationVSAvoidedge node management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple carriers share a single physical IoT gateway infrastructure. The gateway is virtualized to provide logical isolation while physically consolidating resources, eliminating the need for separate dedicated gateways for each carrier and reducing installation space requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single shared gateway is segmented into multiple virtual network instances, each dedicated to a specific carrier. This segmentation provides logical isolation and security boundaries while maintaining physical consolidation, resolving the contradiction between isolation requirements and device complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If dedicated IoT gateways are deployed for each carrier, then data security and isolation are improved, but installation cost and space requirements increase

Engineering Contradiction:
Improvedata securityVSAvoidinstallation cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Multiple carriers share a single physical IoT gateway infrastructure through virtualization. This consolidation reduces the total quantity of hardware devices required, lowering installation costs while maintaining data security through logical isolation mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Instead of deploying physical copies of gateways for each carrier, virtual copies are created through software-defined network instances. This allows multiple carriers to have dedicated logical gateways without the cost of physical hardware multiplication.

Inventive Principle:
Principle #26Copying

3Device complexity

If virtual network functions are shared, then device complexity is reduced, but network isolation and security may be compromised

Engineering Contradiction:
Improveedge node managementVSAvoidnetwork isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The shared physical gateway is segmented into multiple isolated virtual network instances, each dedicated to a specific carrier. This segmentation maintains network isolation and security boundaries while enabling resource sharing, resolving the contradiction between device complexity reduction and reliability maintenance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A virtualization layer acts as an intermediary between the shared physical infrastructure and individual carrier networks. This intermediary provides logical isolation and security enforcement while enabling efficient resource sharing, preventing direct interference between carrier networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3425854B1Network system, control device, method for building virtual network, and program
Publication Date: 2021.10.20 NEC CORP
  • EP3425854B1 patent drawingFigure 1
  • EP3425854B1 patent drawingFigure 2
  • EP3425854B1 patent drawingFigure 3

AI summary

The invention resolves various problems faced by networks in which plural data transmitting entities are deployed. A network system is connected to a first physical network comprising: a first data transmission node that transmits data used for a first service and a second data transmission node that transmits data used for a second service and to a second physical network including at least one apparatus for receiving data from the first and the second data transmission nodes, and constructs a virtual network for each service between the first and the second physical networks.