版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
5GService-GuaranteedNetworkSlicing
WhitePaper
Issue V1.0
Date 2017-02-28
ChinaMobileCommunicationsCorporation,HuaweiTechnologiesCo.,Ltd.,DeutscheTelekomAG,Volkswagen
Abstract
Previousgenerationsofmobilenetworksenabledvoice,data,video,andotherlife-changingservices.Incomparison,5Gwillchangeoursocietybyopeningupthetelecomecosystemtoverticalindustries.5Gwillhelpverticalindustriestoachievethe“InternetofEverything”visionofubiquitouslyconnected,highlyreliable,ultra-lowlatencyservicesformassivenumberofdevices.Service-guaranteednetworkslicingintroducedinthiswhitepaperisoneoftheessen-tialfeaturesfor5Gtoachievethisvision.Keyplayersfromoperators,vendors,andverticalindustrieshavecometogethertoestablishacommonunderstandingonservice-guaranteednetworkslicingintermsofthevision,end-toend(E2E)solution,keyenablingtechnologies,andtheimpactsforverticalindustries.Thiswhitepaperdescribesthethinkingonnetworkslicingin5G.
TableofContents
IndustryTrendsandRequirements 02
VisionsofService-GuaranteedNetworkSlicing 04
OverallArchitectureofService-guaranteedNetworkSlicing 06
Concepts 06
ConceptClarifications 06
Architecture 07
KeyTechnologiestoEnableService-GuaranteedNetworkSlicing 09
NetworkManagementSystem 09
NetworkSliceManagement(NSM)Architecture 09
NetworkCapabilityExposureviaBusinessSupportSystem 10
Third-partyApplications 11
Security 11
InfrastructureSecurity 11
NetworkManagementSecurity 11
NSISecurity 12
EnablingTechnologiesforDifferentTechnicalDomains 12
AccessNetwork 12
CoreNetwork 14
TransportNetwork 15
Terminal 17
TechnologyEvolution 17
UseCaseforService-GuaranteedNetworkSlicing 18
SummaryandSuggestions 20
02
03
IndustryTrendsandRequirements
The5Gnetworksarenotonlyenvisionedasasupportfor“InternetofThings”(IoT),butalsoasmeanstogiverisetoanunprecedentedscaleofemergingindustries,instillinganinfinitevitalityinfuturetelecommunications.IoTrequiressupportforadiverserangeofservicetypes,suchaseHealth,InternetofVehicles(IoV),smarthouseholds,industrialcontrol,environmentmonitoring,andsoon.TheseserviceswilldrivetherapidgrowthofIoTandfacilitatehundredsofbillionsofdevicestoconnecttothenetwork,whichalsoconceivesthe“InternetofEverything”visionespeciallyfromverticalindustries.
TherequirementsforIoTservicesarealsovery
Servicediversity
Theservicesforeseeninthe5Gerafallintothreetypicalscenarios:enhancedMobileBroadband(eMBB),Ultra-ReliableandLowLatencyCommu-nications(URLLC),andmassiveMachineTypeCommunications(mMTC).eMBBfocusesonservicescharacterizedbyhighdatarates,suchashighdefinition(HD)videos,virtualreality(VR),augmentedreality(AR),andfixedmobileconver-gence(FMC).URLLCfocusesonlatency-sensitiveservices,suchasself-driving,remotesurgery,ordronecontrol.mMTCfocusesonservicesthathavehighrequirementsforconnectiondensity,suchasthosetypicalforsmartcityandsmartagricultureusecases.Eachscenariorequiresacompletelydifferentnetworkserviceandposesrequirementsthatareradicallydifferent,some-timesevencontradictory.
diverse.Servicessuchassmarthouseholds,smartgrid,smartagriculture,andintelligentmeterreading,willrequiresupportinganextremelylargenumberofconnectionsandfrequentlytransmittedsmalldatapackets.Servicessuchassmartvehiclesandindustrialcontrolwillrequiremillisecond-levellatencyandnearly100%reliability,whileinfotainmentserviceswillrequireextremefix/mobilebroad-bandconnectivity.Theserequirementsindicatethatthe5Gnetworksneedbemoreflexibleandscalabletosupportmassiveconnectionsofdifferentnature.Meanwhile,operatorswillperformagradualshiftawayfrompipeservicestowardscopingwithverticalindustryneeds:
Guaranteedperformance
Severalkeyperformanceindicators(KPIs)mustbesimultaneouslysatisfiedforsomeoftheabove-mentionedservices.Forexample,VRandARhavestrictrequirementsondatarateaswellaslatency.Suchdemandsbecomemorestrin-gentforverticalindustries,wheretheterminalsarenormally"machines"withverylowtoleranceonperformancedegradation.
Fastdeploymentandshorttime-to-market(TTM)
Itisalongprocesstodeployconventionalmobilenetworks.Asimpleserviceupdatemaytakefrom10to18months.SuchlongcyclesareverydifficulttomeettailoredandfastserviceprovisioningandshortTTMdemandsfromverticalindustries.
ResourcemultiplexingandisolationDifferentfromcurrenttelecompractice,verticalindustriesarelikelytogetinvolvedwithspecial-izednetworkfunctions(dedicatedrouting,mobilitysupport,customizedflowhandling,
in-networkprocessing,etc.).Tohandlesuchdiversitywithoutlosingoperationefficiency,operatorsprefertouseresourcemultiplexingapproachwithsecuredisolationprovisioning.
Automation
Flexibilityandscalabilityarethekeyfeaturesofthe5Gnetworks.Suchnetworkscannotdependonmanualmanagement.Fullyautomaticnetworkmanagementtechniques,suchasself-diagnosis,self-healing,automaticconfiguration,self-optimization,andautoinstallation/plug-and-play,arefundamentaltoachieveefficientnetworkoperationsandtoprovidethedynamicservicemix.Withtheprogressoftheautomaticnetworkmanagementtechniques,managementwillbecomemoreagileandmoreadaptive.Newtoolsforsuchmanagementarerequired;inparticular,artificialintelligence(AI)andauto-maticlearningtechniquesshouldbeconsideredforthe5Gnetworks.
NewecosystemandbusinessmodelThe5Gnetworkswillsupportnewrolesandbusinessmodels,whichmayinvolvenetworkinfrastructureproviders,operators(mobilenetworkoperators,mobilevirtualnetworkoperators,etc.),andverticalserviceproviders.Thesenewrolesandbusinessrelationshipshelpthetelecomindustrytobuildanewecosystemtogetherwithverticalindustries.
ConvergenceoffixedandmobileaccessFMCisalsoaveryimportantrequirement,becausecustomersdoexpectthesameuserexperienceregardlessoftheaccesstechnologyused.Whiletodaythearchitectures,serviceconceptsandecosystemsoffixedandmobilenetworksdifferinmanyaspects,itisenvisionedthatwith5Gthesewillconverge.Anarchitecturethatcannativelyhandleallkindsoffixedandmobileaccesstechnologieswillcontributesignificantlytoenablethedesigngoaloftrulyconverged5Gnetworks.
04
05
VisionsofService-GuaranteedNetworkSlicing
Inthe5Gera,verticalindustrieswilltriggerthenetworkstoshiftfromthetraditional
“human-centric”servicesto“machine-centric”services.Thisnotonlyallowsthe
Vision1:Provideguaranteedperformancetomeetthefundamentalservicerequire-mentsofverticalindustries.
Uponthefundamentalconnectivityservice,guaranteedperformance(e.g.,latency,datarate,reliability,connectivity,andpowerconsumption)willenableoperatorstoembraceverticalindus-triesin5Gecosystem.Guaranteedperformanceisnotonlyaboutqualityofservice(QoS),italsoimpliescustomizednetworkfunctionsandresourcestotackledifferenttypesofservices,forinstance,toprovidevehicle-to-everything(V2X)servicewithcustomizedmobilitymanagement.
Vision2:Providecustomizedservicestoenhancethecompetenceofverticalindustries.
Provisioningaguaranteedperformanceisonlythebasicpropositiontocooperatewithverticalindustriesin5G.Thefurtheressentialsteptowardssuccessistobringmoreconcretevaluefortheverticalservices,forinstance,reducingtheirserviceoperationalcostandcapitalcost,shorteningTTM,etc.Helpingverticalindustriestoincreasetheircompetenceisavitalcomponentof
telecommunicationindustrytodevelopanewecosystem,butalsobecomesthenewenginetoboostthesocialeconomywiththefollowingcorevisions:
the5Gecosystem.
Basedonthefundamentalconnectivityservices,operatorsshouldinvokedeeperbusinesspoten-tialsviaprovidingcustomizedservices,forinstance:
Networkservices:Thenetworkcapabilities,e.g.,caching,canbeusedtoenhanceverticalserviceperformance.
Resourceservices:Verticalindustriesareencouragedtodeploytheirservicesintheoperator’sedgedatacenters(DCs)andcoreDCs,becauseoperatorscouldusetheadvantageoftheorchestrationofnetworkandcloudresource,aswellasedgecomputing.
Networkoperationandmaintenance(O&M)services:IndependentO&Maccordingtocustom-izedpoliciesisanappealingfeatureforverticalindustries.
Terminal
CustomizedService
Vertical
third-partyservices
ResourceService
NetworkO&MService
NetworkService
ConnectivityService
EdgeDC
CoreDC
IndustryControlAPPs
V2XAPPs
Smart-meterApps
·Figure1:Service-guaranteednetworkslicingvision
Aspresentedabove,theflexibilityanddiversityexpectationsfromthecorevisionsarerealandtremendous.Thequestionishowtofulfillthese:theflexibilityofservicesontheonehandandthediversityofnecessarynetworktechnologiesontheotherhandposeadauntingrequirementonthenetworkdesign,control,operationsandmanagement.Suchasystembearsahighriskofcrumblingunderitsowncomplexity.Toovercomethesechallengeswhilestillfulfillingtheexpectedfuturedemands,aservice-guaranteednetworkslicingisintroducedinthiswhitepaper,aimingtorealizetheabovecorevisions.Itproposestohave
severallogicalnetworkswithdifferentnetworkservices,provisions,mechanisms,orassurancesonthesameinfrastructure.Verticalindustriesinterestedinthesupportedservicesthereforewouldonlyberequiredtoconcentrateonthemanagementofthenetworkslicingspecificprovisions,tightlycoupledwiththeexpectedservices.Suchconcentrationonthebusinessneedsensuresinterestandcompetenceofverticalindustriesontheonehandand,ontheotherhand,offloadthemfromcomplexconsiderationsofdesigning,deploying,testingandrunningsuchnetworks.
06
07
OverallArchitectureofService-guaranteedNetworkSlicing
Concepts
Since“networkslicing”appearedinthe5Gvocabulary,anumberofconceptshavebeenderivedfromit,i.e.networkslicinginstance,networkslicetype,etc.Thissectionaimstoclarifythedefinitionoftheseconceptsandtheircorrespondingrelationships:
Networkslicing:Networkslicingisthecollec-tionofasetoftechnologiestocreatespecialized,dedicatedlogicalnetworksasaservice(NaaS)insupportofnetworkservicedifferentiationandmeetingthediversifiedrequirementsfromverticalindustries.Throughflexibleandcustom-izeddesignoffunctions,isolationmechanisms,andO&Mtools,networkslicingiscapabletoprovidelogicaldedicatednetworksuponacommoninfrastructure.
Networksliceinstance(NSI):AnNSIistherealizationofnetworkslicingconcept.ItisanE2Elogicalnetwork,whichcomprisesofagroupofnetworkfunctions,resourcesandconnectionrelationships.AnNSItypicallycoversmultipletechnicaldomains,whichincludesterminal,accessnetwork(AN),trans-portnetwork(TN)andcorenetwork(CN),aswellasDCdomainthathoststhird-partyapplicationsfromverticalindustries.DifferentNSIsmayhavedifferentnetworkfunctionsandresources.Theymayalsosharesomeofthenetworkfunctionsandresources.
Networkslicetype:Networkslicetypesarehigh-levelcategoriesforNSIs,whichreflectthedistinctdemandsfornetworksolutions.Three
fundamentalnetworkslicetypeshavebeenidenti-fiedfor5G:eMBB,mMTC,andURLLC.Thesecouldbefurtherextended,e.g.accordingtotheoperator’spoliciesorwiththedevelopmentof5G.
Networkslicetemplate:NetworkslicetemplateistheoutputoftheslicedesignphaseusedtocreateNSIs.
Tenant:Tenantsaretheoperators'customers(forexample,customersfromverticalindustries)ortheoperatorsthemselves.TheyutilizetheNSIstoprovideservicestotheirusers.TenantstypicallywillhaveindependentO&Mrequire-ments,whichareuniquelyapplicabletotheNSIs.
ConceptClarifications
Theaforementionedkeyconceptshavethefollowingrelationships.
NetworkslicetypesandtenantsareimportantreferencesforcreatinganNSI.AnNSIisinstanti-atedfromonenetworkslicetemplatewithaspecificnetworkslicetype.AtenantthatprovidesdifferentservicetypesmayusemultipleNSIswithdifferentnetworkslicetypes.Fortenants,whomayprovideservicesofthesameservicetype,theycanstillusedifferentiatedNSIsviathe
customizationofthenetworkslicetemplatewiththesamenetworkslicetypes.
NetworkslicetemplatedesignisseparatefromtheNSIoperation.Inthedesignphase,thenetworkslicetemplateisgeneratedbasedonthenetworkcapabilityofeachtechnicaldomainandatenant'sparticularrequirements.Intheopera-tionphase,anNSIisinstantiatedbasedonthenetworkslicetemplate,whichincludesthedeploymentandconfigurationofrelatednetworkfunctionsandrelatedresourcesindifferenttechnicaldomains.Thenetworkslicedesignisseparatefromtheoperationtoenabletherepeateduseofanetworkslicetemplate.
NSIsrequiremulti-dimensionalmanagement.AnNSIusuallyincludesmultipletechnicaldomains.AnNSImayalsoincludemultipleadministrativedomainsthatbelongtodifferentoperators.ToguaranteeNSI’sfastdeployment,itisessentialtouseefficientmulti-dimensionalmanagementviacoordinationandcooperationacrosssuchdifferentdomains.
NSIsensureSLAcompliance.Tenantswillsignservice-levelagreement(SLA)withoperators,whichmayincluderequirementagreementsrelatedtosecurity/confidentiality,visibility/manageability,specificservicecharac-teristics(servicetype,airinterfacestandard,andcustomizedfunctions),andcorrespondingperformanceindicators(latency,throughput,packetlossrate,calldroprate,andreliability/availability).
TerminalsmaybeinvolvedintheselectionofNSIs.TerminalscanaccessoneormultipleNSIs.TerminalscouldassistNSIselectionbasedon,forinstance,networkslicetype,whilethenetworkperformsthefinalselectiondecision.Simpleterminals,suchassensors,areusuallyinastaticandone-to-onerelationshipwithNSIs,becausethecostsandpowerconsumptionrequirementslimittheterminalcapability.Therefore,theNSIselectionissolelyperformedbythenetwork.
Architecture
Enablingnetworkslicingin5Grequiresnativesupportfromtheoverallsystemarchitecture.AsshowninFigure2,theoverallarchitectureconsistsofthreefundamentallayers:theinfra-structurelayer,networkslicelayerandnetworkmanagementlayer.Theinfrastructurelayerprovidesthephysicalandvirtualizedresources,forinstance,computingresource,storageresource,andconnectivity.Thenetworkslicelayerrunsabovetheinfrastructurelayerandprovidesnecessarynetworkfunctions,toolsandmechanismstoformend-to-end(E2E)logicalnetworksviaNSIs.ThenetworkmanagementlayercontainsthegenericBSS/OSSandnetworkslicemanagement(NSM)system,whichdesignsandmanagesnetworkslicing.Moreover,italsoassurestheSLArequirements.
Theoverallarchitecturehasthefollowingkeyfeatures:
Commoninfrastructure:Beingdifferentfromthededicatednetworksolutionthatusesphysi-callyisolatedandstaticnetworkstosupporttenants,networkslicingpromotestheuseofacommoninfrastructureamongtenantsfromthesameoperator.IthelpstoachievehigherresourceutilizationefficiencyandreducetheserviceTTM.Moreover,suchdesignisbeneficialforlong-termtechnologyevolutionaswellasforshapingahealthyindustryecosystem.
On-demandcustomization:EachtechnicaldomaininanNSIhasdifferentcustomizationcapabilities,whicharecoordinatedthroughtheNSMsystemduringtheprocessofnetworkslicetemplatedesign,andNSIdeploymentandO&M.Eachtechnicaldomaincanperformanindepen-denttailoring-processintermsofdesignschemestoachieveaneffectivebalancebetweenthesimplicityneededbycommercialpracticeandarchitecturalcomplexity.
Isolation:TheoverallarchitecturesupportstheisolationofNSIs,includingresourceisola-tion,O&Misolation,andsecurityisolation.NSIs
08
09
canbeeitherphysicallyorlogicallyisolatedatdifferentlevels.
Guaranteed-performance:Networkslicingseamlesslyintegratesdifferentdomainstomeetandensureindustry-defined5Gperformancespecificationsandtoaccommodateverticalindustryrequirements.
Scalability:Duetovirtualization,whichisoneofthekeyenablingtechnologiesfornetworkslicing,resourcesoccupiedbyanNSIcandynamicallychange,e.g.,scalingin/out.
O&MCapabilityExposure:Tenantsmayusededicated,sharedorpartiallysharedNSIs.
Furthermore,differenttenantsmayhaveinde-pendentO&Mdemands.TheNSMsystemprovidesaccesstoanumberofO&MfunctionsofNSIsforthetenants,whichforinstanceallowsthemtoconfigureNSIsrelatedparameters,e.g.,policy.
Supportformulti-vendorandmulti-operatorscenarios:Networkslicingallowsasingleopera-tortomanagemultipletechnicaldomains,whichmaybecomposedofnetworkelementssuppliedbydifferentvendors.Inaddition,thearchitecturealsoneedstosupportthescenario,wheretheservicesfromthetenantsmaycoverdifferentadministrativedomainsownedbydifferentoperators.
NSIA
Third-party“BSS”
Third-party“BSS”
BSS
NSIB
AN
OSS
NetworkSliceManagementSystem
AP
EdgeDC
CoreDC
Terminal AccessNetwork TransportNetwork CoreNetwork 3rdpartyAPP
CommonInfrastructure
AN
·Figure2:Overallarchitecturetoenablenetworkslicing
KeyTechnologiestoEnableService-GuaranteedNetworkSlicing
NetworkManagementSystem
NetworkSliceManagement(NSM)Architecture
TheNSMsystemplaysanimportantroleintheentiresystemarchitecture.Itprovidesthefollow-ingservices:
Design:designnetworkslicetemplatesaccordingtothenetworkcapabilitiesandSLArequirements.
Provisioning:comprisesliceinstantiation,configuration,andactivation.
Runtimeassurance:observetherunningstatusofNSIsandensureSLA.
Decommissioning:deleteanNSIwhenitsservicesarenotusedanymore.
TheNSMshallbebasedonthestateoftheartcloudmanagementtechnologieswithenhancedfeaturestosupportnetworkslicing.ItprovidesO&Mcapabilityusingastreamlineofaforemen-tionedservices,whichaddressinadequaciesofthetraditionalnetworkmanagementsystem,e.g.,longTTMorlackofautomaticO&Mmethods.TheNSMsystemcouldfurtherhelpoperatorstoestablishanopenecosystemtoenablenewbusinessopportunities.
Figure3depictstheoverallNSMsystemarchi-tecture,whichuses“Layer-andDomain-basedmanagement”designprinciple.“Layer-based”managementdefinestwolayerswithintheNSM:slicesupportsystem(SSS)anddomainslicesupportsystem(DSS).“Domain-based”manage-mentimpliesthatthebasiccapabilitiesareprovidedbyeachindividualtechnicaldomain.ThecooperationbetweentheDSSandSSSguaran-teestheE2ESLA.
SliceSupportSystem(SSS)
TheSSSmainlycomprisestwofunctionalblocks:theNetworkSliceTemplateDesignerandtheCrossDomainSliceManager.Theformergener-atesthenetworkslicetemplateaccordingtothenetworkcapabilityofeachtechnicaldomainaswellasthefunctionalandperformancerequire-mentsfromthetenants.ThelatterisresponsiblefortheNSIlifecyclemanagement(i.e.provision-ing,runtimeassurance,anddecommissioning).TheSLAisguaranteedthroughmulti-dimensionalcoordinationamongdifferentdomains.Basedonthecapabilityofeachtechnicaldomain,theSSSdecomposesanSLAintermsofsetsofrequire-mentsandmapseachsegmentofSLAtothecorrespondingtechnicaldomain.ToensuretheoverallSLA,theSSSaggregatesthenetworkserviceperformancefromeachindividualtechni-
PAGE
10
PAGE
11
caldomain.Basedonthis,theSSSperformsnecessaryadjustmentsandconfigurationstoensureclosed-loopcontrol.
Tosupportmanagementacrossdifferentadmin-istrativedomainsfordifferentoperators,theinterworkingbetweendifferentSSSsiscompulsory.
DomainsliceSupportSystem(DSS)
TheDSScomprisestheDomainSliceManagers(DSMs)fordifferenttechnicaldomains:accessnetworkDSM(AN-DSM),corenetworkDSM(CN-DSM),andtransportnetworkDSM(TN-DSM).Asalogicalentity,theDSMisresponsibleforthedesign,provisioning,runtimeassurance,anddecommis-sioningofsubnetsinasingletechnicaldomain.The
DSSensuresthereal-timeguaranteefordecom-posedSLAcapabilitiesineachdomain,e.g.viamonitoringandfaultlocalization.EachdomainhasindependentSLA-specificclosed-loopcontroloffunctionsandresourcesforfastserviceschedulingandresourceoptimization.
ThetaskoftheNSMsystemisnotonlyaboutseamlesslymanagingandassuringtheSLA,togetherwithadvancedAIalgorithms,itcouldalsopredictthenetworkstatuschangesinordertoprovidecertainmanagementandcontrolactionsforprecaution.TheNSMsystemcouldbestandalone(anewmanagemententity)ornon-standalone(integratedwithOSS).
BBS
NetworkSliceManagementSystem
SSS
NetworkSlice
T
emplateDesigner
DDS
1:N
1:N
1:N
AP
EdgeDC
Terminal
AN(1…n)
TN(1…n)
CoreDC
CN(1…n) 3ndPartyApp
CN-DSM
TN-DSM
AN-DSM
CrossDomainSliceManager(multi-vendor)
·Figure3:Networkslicemanagement(NSM)architecture
OSS
NetworkCapabilityExposureviaBusinessSupportSystem
TheBusinessSupportSystem(BSS)fromopera-torsisdirectlyfacingthetenants.Therefore,itsusabilityisanessentialfactor.OperatorsusetheBSStoprovidetheirabstractednetworkcapabilitytothetenants.Itmainlysupportsthefollowing
capabilities:design,purchasing,deployment,andmonitoring.
Designincludesthedesignandofferingofcommercialproductsrelatedtonetworkslicing.Basedontheservicetypesandtenants’require-ments,theSLAisformulated.ApurchasableproductmayuseoneormoreNSIstoaccommodate
thetenants’service.SuchproductwithpackagedNSIsisusedasanofferingforthetenants,whichfocusonthecommercialattributesofproducts,suchas,pricingandsalesterritory.
Purchasingisthekeypartfortheuserexperienceofthetenants.Forinstance,itisessentialfortheBSStohaveawell-designedstorepagefordisplay-ingtheproductsandpersonalcenterformonitoringthepurchasingprogressandtriggeringnetworkservicerelatedupgradingprocess.
DeploymentofaproductistriggeredbytheBSSafterasuccessfulcustomerpurchase.
MonitoringreferstotheBSScapabilityofallow-ingtenantstoviewtheoperationalaswellasperformancerelatedinformationfortherunningservices,e.g.,throughputandlatencyofcertainNSIs.
Third-partyApplications
Theflexibilityandcustomizationofnetworkslicingarealsoreflectedintheaccommodationofthird-partyapplications.Inadditiontothevariousnetworkfunctionsprovidedbyoperators,itisalsofeasibletodeploythird-partyapplicationsonNSIstomeetthespecificrequirementsfromthetenants.Such
third-partyapplicationscouldbefromtenantsdirectly,orfromnon-tenantparties(e.g.,tenants’customerorprovider).
Themainreasontosupportthedeploymentofthird-partyapplicationsistoenableserviceswithspecificrequirements,suchas,URLLCservices
requiringultra-lowlatency.Itisbeneficialtoreducethelengthofthetransmissionpathbymovingthenetworkfunctionsandthird-partyapplicationsclosetotheAN,e.g.,leveragingtheadvantageofedgecomputing.
Inaddition,third-partyapplicationscanalsoprovidesubstitutionofnetworkfunctions,suchasuser-customizedauthenticationandmobilitymanage-ment,whicharedesignedespeciallytosupporttheirownservices.Otherthancontrolplanerelatednetworkfunctions,customizeduserplanenetwork
functions,suchasservicegatewayfromtenantscanbealsodeployedwithintheoperatornetworks.Thiswouldenablepreliminaryfiltrationandaggregationofalargeamountofdata(e.g.,fromsensors).TheNSMsystemshouldthussupportthedeploymentofthird-partyapplications.Thedeploymentpositionscanbeeitherspecified,e.g.,inanAN,CN,ordynami-callydeterminedbytheSSSbasedonservicerequirementsandnetworkconditionsduringthenetworkslicedesignphase.
Security
Theoverallarchitecturedefinedintheprevioussectioncontainsthreefundamentallayers:theinfrastructure,networkslice,andnetworkmanage-mentlayer.Eachlayermustconsideritsindividualsecurityrisksandprotectionmechanisms.More-over,itisnecessarytoconsideralldomainstogetherasanorganicwholetoprovideoverallsecurity.Ingeneral,thereexistthefollowingthreeaspectsinaholisticframeworkofnetworkslicesecurity.
InfrastructureSecurity
AsNSIsaresharingthesameinfrastructure,properisolationbetweenNSIsmustbeenforcedtoavoidadversecross-effectsandinformationleakage,especiallywhenNFVisused.Forexample,differentvirtualmachinesorcontainersareusedfordifferentnetworkfunctionsandthevirtuallinksconnectingVNFsdedicatedfordifferentNSIsshouldbelogicallyisolated.
NetworkManagementSecurity
SecurityrisksexistineveryphaseoftheNSIlifecyclemanagementinthenetworkmanagementlayer.
Maliciousattacksmayusemalwaretocompromiseanetworkslicetemplate,threateningallsubse-quentNSIs.Attacksmayalsopassthroughconfigu-rationinterfacesduringtheruntimephaseofanNSI.Confidentialdatacouldbeobtainedduringthedecommissioningphase,iftheNSIishandledimproperly.Therefore,thesecurityconsiderationsshouldcovereachsinglestepofthelifecycleman-agementofNSIs.
Assomenetworkcapabilitiesandinterfacesareexposedtotenants,thecapabilitiesgrantedtoaparticulartenantaredefinedbytheoperator.
Tenantsmustbeauthenticatedandauthorizedbeforebeingallowedtoaccessthesecapabilitiesandinterfaces.
NSISecurity
ToguaranteesecurityforthenetworkservicesprovidedbyanNSI,itrequiresembeddingthesecuritymechanismandsecurityprovisioningentity(e.g.securityanchorsandsecurityfunctions)intothelogicalnetworkarchitectureoftheNSI.
Securityisolation:Withoutsecurityisolation,maliciousattackswithaccesstooneNSImayusethatNSIasalaunchingpadforattackingotherNSIsby,forinst
溫馨提示
- 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 汽車模具2025版性能優(yōu)化開(kāi)發(fā)合同
- 2025年度木材出口合同范本與執(zhí)行細(xì)則4篇
- 2025版學(xué)校小賣部與校園周邊商家聯(lián)盟合同3篇
- 2025版建筑設(shè)備安裝工程安全生產(chǎn)消防合同3篇
- 2025版外語(yǔ)教學(xué)機(jī)構(gòu)兼職外教招聘合同樣本3篇
- 2025年人力資源服務(wù)合同解除協(xié)議
- 2025年前雇主員工競(jìng)業(yè)禁止合同樣本模板
- 2025版?zhèn)€人合伙退伙協(xié)議書糾紛處理指南4篇
- 2025年云石打邊蠟水項(xiàng)目投資可行性研究分析報(bào)告
- 2025年度駱采與陳鵬的離婚財(cái)產(chǎn)分割及子女撫養(yǎng)權(quán)合同4篇
- GB/T 45107-2024表土剝離及其再利用技術(shù)要求
- 2024-2025學(xué)年八年級(jí)上學(xué)期1月期末物理試題(含答案)
- 商場(chǎng)電氣設(shè)備維護(hù)勞務(wù)合同
- 2023年國(guó)家公務(wù)員錄用考試《行測(cè)》真題(行政執(zhí)法)及答案解析
- 2024智慧醫(yī)療數(shù)據(jù)字典標(biāo)準(zhǔn)值域代碼
- 年產(chǎn)12萬(wàn)噸裝配式智能鋼結(jié)構(gòu)項(xiàng)目可行性研究報(bào)告模板-立項(xiàng)備案
- 【獨(dú)家揭秘】2024年企業(yè)微信年費(fèi)全解析:9大行業(yè)收費(fèi)標(biāo)準(zhǔn)一覽
- 醫(yī)療器械經(jīng)銷商會(huì)議
- 《±1100kV特高壓直流換流變壓器使用技術(shù)條件》
- 1-1 擁抱夢(mèng)想:就這樣埋下一顆種子【2022中考作文最熱8主題押題24道 構(gòu)思點(diǎn)撥+范文點(diǎn)評(píng)】
- 《風(fēng)電場(chǎng)項(xiàng)目經(jīng)濟(jì)評(píng)價(jià)規(guī)范》(NB-T 31085-2016)
評(píng)論
0/150
提交評(píng)論