VNF Physical Network Segregation for Isolated Access and Core Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Network Function Virtualization (NFV), there is a security concern where malicious entities can launch denial-of-service attacks affecting both access and core networks due to shared physical cables for data traffic between Virtual Network Functions (VNFs) and networks, compromising network integrity.
Innovation Solution
Configuring datacenters to segregate core and access network traffic by using distinct physical cables for each network, ensuring that VNFs communicate with the access network through one interface and the core network through another, isolating traffic paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If shared physical cables are used for data traffic between VNFs and networks, then device complexity is reduced and resource utilization is improved, but network security deteriorates as attacks can affect both access and core networks simultaneously
Solution Approach 1:
The patent applies segmentation by dividing the network infrastructure into separate physical networks for access network traffic and core network traffic. This is achieved through configuring separate physical network interfaces on physical machines, creating distinct network paths that prevent attacks from propagating between access and core networks while maintaining resource virtualization benefits
2Object-affected harmful factors
If separate physical cables are used for core and access network traffic, then network security is improved by isolating traffic paths, but device complexity increases due to additional network interfaces and configuration
Solution Approach 1:
The patent applies universality by enabling physical machines to serve multiple functions through configuring multiple network interfaces that can be dynamically allocated. The same physical infrastructure supports both access and core network functions with proper isolation, reducing the need for completely separate hardware systems while maintaining security
Data Source
AI summary
A method includes, with a Virtual Network Function (VNF) component associated with a VNF, communicating with an access network over a first physical network connected to a first physical network interface of a physical machine associated with the VNF component. The method further includes, with the VNF component, communicating with a core network over a second physical network connected to a second physical network interface of the physical machine, the second network being isolated from the first network.


