VNF Physical Network Segregation for Isolated Access and Core Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Network Function Virtualization (NFV), there is a security concern where malicious entities can launch denial-of-service attacks affecting both access and core networks due to shared physical cables for data traffic between Virtual Network Functions (VNFs) and networks, compromising network integrity.

Innovation Solution

Configuring datacenters to segregate core and access network traffic by using distinct physical cables for each network, ensuring that VNFs communicate with the access network through one interface and the core network through another, isolating traffic paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If shared physical cables are used for data traffic between VNFs and networks, then device complexity is reduced and resource utilization is improved, but network security deteriorates as attacks can affect both access and core networks simultaneously

Engineering Contradiction:
Improvenetwork infrastructure complexityVSAvoidnetwork security vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the network infrastructure into separate physical networks for access network traffic and core network traffic. This is achieved through configuring separate physical network interfaces on physical machines, creating distinct network paths that prevent attacks from propagating between access and core networks while maintaining resource virtualization benefits

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If separate physical cables are used for core and access network traffic, then network security is improved by isolating traffic paths, but device complexity increases due to additional network interfaces and configuration

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling physical machines to serve multiple functions through configuring multiple network interfaces that can be dynamically allocated. The same physical infrastructure supports both access and core network functions with proper isolation, reducing the need for completely separate hardware systems while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250260622A1Isolated Physical Networks for Network Function Virtualization
Publication Date: 2025.08.14 RIBBON COMMUNICATIONS OPERATING CO INC
  • US20250260622A1 patent drawing
  • US20250260622A1 patent drawing
  • US20250260622A1 patent drawing

AI summary

A method includes, with a Virtual Network Function (VNF) component associated with a VNF, communicating with an access network over a first physical network connected to a first physical network interface of a physical machine associated with the VNF component. The method further includes, with the VNF component, communicating with a core network over a second physical network connected to a second physical network interface of the physical machine, the second network being isolated from the first network.