Network slicing is one of the most important features in 5G which enables a large variety of services with diverse performance requirements by network virtualization. Traditionally, the network can be viewed as a one-...Network slicing is one of the most important features in 5G which enables a large variety of services with diverse performance requirements by network virtualization. Traditionally, the network can be viewed as a one-size-fits-all slice and its services are bundled with proprietary hardware supported by telecom equipment providers. Now with the network virtualization technology in 5G, open networking software can be deployed flexibly on commodity hardware to offer a multi-slice network where each slice can offer a different set of network services. In this research, we propose a multi-slice 5G core architecture by provisioning its User Plane Functions (UPFs) with different QoS requirements. We compare the performance of such a multi-slice system with that of one-size-fits-all single slice architecture under the same resource assignment. Our research objective is to compare the performance of a network slicing architecture with that of a “one-size-fits-all” architecture and validate that the former can achieve better performance with the same underlying infrastructure. The results validate that our proposed system can achieve better performance by slicing one UPF into three with proper resource allocation.展开更多
第五代移动通信网络5G以融合网络为目标,其标准不仅覆盖公共通信网络,也同时应用于下一代垂直行业网络。传统垂直行业网络是以工业自动化和控制系统为主的运营/操作技术(Operational Technology,OT)网络,OT网络采取安全域划分方式,将大...第五代移动通信网络5G以融合网络为目标,其标准不仅覆盖公共通信网络,也同时应用于下一代垂直行业网络。传统垂直行业网络是以工业自动化和控制系统为主的运营/操作技术(Operational Technology,OT)网络,OT网络采取安全域划分方式,将大规模复杂系统分为不同安全子区域,在边界处部署专用安全设备/系统进行安全防护。目前实践中多采用网闸等设备以硬隔离方式阻断恶意流量,带来的问题是严重影响正常业务的通过。依托5G的网络功能虚拟化(Network Function Virtualization,NFV)技术和软件定义网络(Software Defined Network,SDN),本文提出了一种面向5G网络的动态安全边界防护机制。该机制构建虚拟化的边界网络安全功能资源池和边界安全服务规则库,对到达边界的业务流量进行防护等级分析,并根据规则库中的规则动态生成边界安全服务功能链。机制还具备对边界服务功能链进行优化部署的能力,通过建模和启发式算法实现满足业务防护等级需求和最小化处理时延的多目标优化部署策略。基于本机制,我们设计并提出轨交行业5G专网动态安全边界防护机制实例,旨在为工程实践服务。最后,我们搭建了基于Mininet+Ryu仿真平台,模拟轨交行业5G示范网络中的安全域组成和边界安全能力,并对机制进行实验验证,结果表明,该机制能够有效地动态生成边界服务功能链并且达到控制不同防护等级业务流量通过的目标。展开更多
网络切片作为软件定义网络(software defined networking,SDN)技术框架体系的核心内容,已经成为5G网络演进过程中一项关键技术特性。同时,5G网络演进中的无线接入网络对泛在接入需求的进一步提升,使无线资源管理也必定要围绕着资源虚拟...网络切片作为软件定义网络(software defined networking,SDN)技术框架体系的核心内容,已经成为5G网络演进过程中一项关键技术特性。同时,5G网络演进中的无线接入网络对泛在接入需求的进一步提升,使无线资源管理也必定要围绕着资源虚拟化和设计切片化为重点展开技术演进。从无线网络切片技术的需求和功能场景定义出发,讨论分析了网络切片技术在无线资源管理中的研究现状,进而给出其在无线接入网络设计中所面临的挑战,为后续研究和系统演进提供指导。展开更多
文摘Network slicing is one of the most important features in 5G which enables a large variety of services with diverse performance requirements by network virtualization. Traditionally, the network can be viewed as a one-size-fits-all slice and its services are bundled with proprietary hardware supported by telecom equipment providers. Now with the network virtualization technology in 5G, open networking software can be deployed flexibly on commodity hardware to offer a multi-slice network where each slice can offer a different set of network services. In this research, we propose a multi-slice 5G core architecture by provisioning its User Plane Functions (UPFs) with different QoS requirements. We compare the performance of such a multi-slice system with that of one-size-fits-all single slice architecture under the same resource assignment. Our research objective is to compare the performance of a network slicing architecture with that of a “one-size-fits-all” architecture and validate that the former can achieve better performance with the same underlying infrastructure. The results validate that our proposed system can achieve better performance by slicing one UPF into three with proper resource allocation.
文摘第五代移动通信网络5G以融合网络为目标,其标准不仅覆盖公共通信网络,也同时应用于下一代垂直行业网络。传统垂直行业网络是以工业自动化和控制系统为主的运营/操作技术(Operational Technology,OT)网络,OT网络采取安全域划分方式,将大规模复杂系统分为不同安全子区域,在边界处部署专用安全设备/系统进行安全防护。目前实践中多采用网闸等设备以硬隔离方式阻断恶意流量,带来的问题是严重影响正常业务的通过。依托5G的网络功能虚拟化(Network Function Virtualization,NFV)技术和软件定义网络(Software Defined Network,SDN),本文提出了一种面向5G网络的动态安全边界防护机制。该机制构建虚拟化的边界网络安全功能资源池和边界安全服务规则库,对到达边界的业务流量进行防护等级分析,并根据规则库中的规则动态生成边界安全服务功能链。机制还具备对边界服务功能链进行优化部署的能力,通过建模和启发式算法实现满足业务防护等级需求和最小化处理时延的多目标优化部署策略。基于本机制,我们设计并提出轨交行业5G专网动态安全边界防护机制实例,旨在为工程实践服务。最后,我们搭建了基于Mininet+Ryu仿真平台,模拟轨交行业5G示范网络中的安全域组成和边界安全能力,并对机制进行实验验证,结果表明,该机制能够有效地动态生成边界服务功能链并且达到控制不同防护等级业务流量通过的目标。
文摘网络切片作为软件定义网络(software defined networking,SDN)技术框架体系的核心内容,已经成为5G网络演进过程中一项关键技术特性。同时,5G网络演进中的无线接入网络对泛在接入需求的进一步提升,使无线资源管理也必定要围绕着资源虚拟化和设计切片化为重点展开技术演进。从无线网络切片技术的需求和功能场景定义出发,讨论分析了网络切片技术在无线资源管理中的研究现状,进而给出其在无线接入网络设计中所面临的挑战,为后续研究和系统演进提供指导。