IP Library Granted Patent US 12701446
Granted Patent B2
US 12701446 · App. 18/559,668 · Granted Aug 4, 2026

Network slicing performance monitoring and isolation analysis

Inventors: Jing Ping (Chengdu, CN); Iris Adam (Munich, DE); Chaitanya Aggarwal (Munich, DE); Konstantinos Samdanis (Munich, DE)
Assignee: Nokia Technologies Oy
H04W24/08H04L41/0853H04L43/06H04L43/20H04W24/02H04L41/0627H04L41/0654
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701446
App. No.
18/559,668
Granted
Aug 4, 2026
Kind
B2
Abstract

There is disclosed an apparatus comprising means for performing: obtaining data associated with network slice isolation performance; generating analytics information based on the data; and sending the analytics information.

Claims (39)

1 . An apparatus comprising a Management Data Analytics Function (MDAF), the apparatus further comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the MDAF at least to perform:

based on a subscription for an isolation assurance report received from an analytics consumer, sending a request to a Network Data Analytics Function (NWDAF) to collect analytics related to network slice isolation, and obtaining a preliminary analytics report from the NWDAF as a data source;

based on at least one of the subscription or one or more alerts, raised by a first network function upon detecting an error comprising a mismatch of Single Network Slice Selection Assistance information (S-NSSAI) in a received message, requesting and obtaining data associated with network slice isolation performance from at least one core network domain source selected from a group consisting of a second network function comprising an Access and Mobility Management Function (AMF) or a Session Management Function (SMF), a network repository function (NRF), or a core network analytics function, and from at least one management domain source selected from a group consisting of a security function comprising a firewall (FW) or a management function, wherein the data comprises:

data of one or more errors from security logs or trace messages, wherein the errors comprise a control plane message for a first S-NSSAI being delivered to a network function dedicated to a second S-NSSAI, or a data plane packet for a first S-NSSAI being delivered to a user plane function dedicated to a second S-NSSAI;

performance measurements comprising:

a number of failed network function (NF) service register or discovery requests with incorrect Single Network Slice Selection Assistance information,

a number of unauthorized access attempts with incorrect S-NSSAI, or a number of failed NF service discoveries due to an unauthorized NF Service consumer;

the isolation assurance report from the NWDAF;

network topology information;

configuration parameters related to isolation; and

version or release information of one or more network functions;

correlating the data associated with network slice isolation performance with isolation policy information obtained from an isolation policy database;

generating analytics information of an Isolation Assurance analytics type based on the data and the correlation; and

sending the analytics information to the analytics consumer, wherein the analytics information includes:

isolation policy violation statistics,

information of probable cause of isolation policy violation, wherein the probable cause comprises a misconfiguration of a network function, a vulnerable software version of a network function, or a compromised network function,

one or more recommended mitigation steps for mitigating future violation of the isolation policy, wherein the one or more recommended mitigation steps comprise enforcing isolation policies on a security gateway or firewall, isolating or terminating network function identified as malicious, reconfiguring a network function identified as impacted, or upgrading a network function identified as problem function,

an identifier of a type of violation,

performance statistics,

performance prediction information,

information of whether the analytics information pertains to a shared or dedicated resource,

information of a target entity for sending the analytics information,

geographical location information,

information of one or more affected objects, wherein the one or more affected objects comprise a network slice, a network function, a Protocol Data Unit (PDU) session, or subscriber information,

a start time of a performance problem, a stop time of the performance problem, or both the start and stop times of the performance problem, and

a severity level of one or more performance problems.

2 . The apparatus of claim 1 , wherein generating the analytics information further comprises:

determining, based on the obtained version or release information of the first network function, that the probable cause is the vulnerable software version of the first network function.

3 . The apparatus of claim 1 , wherein the one or more recommended mitigation steps comprise recommending to upgrade the first network function in response to the information of probable cause of isolation policy violation identifying a vulnerable software version of the first network function.

4 . The apparatus of claim 3 , wherein the data associated with network slice isolation performance comprises a newly generated event or notification indicating detection of a mismatched Single Network Slice Selection Assistance information (S-NSSAI) in signaling or user plane data received by a network function.

5 . The apparatus of claim 4 , wherein the data further comprises an event generated by a network repository function (NRF) indicating an unexpected network function registration or service discovery request associated with an erroneous or unauthorized S-NSSAI.

6 . The apparatus of claim 5 , wherein the data further comprises an event generated by a security function indicating an attempted communication between network functions allocated to different isolated network slices in violation of an isolation policy.

7 . The apparatus of claim 6 , wherein correlating the data with isolation policy information further comprises obtaining slice association information for network function identifiers included in error logs and determining whether the network functions belong to different S-NSSAIs in violation of the isolation policy.

8 . The apparatus of claim 7 , wherein the data associated with network slice isolation performance comprises trace information collected from at least one of a signaling plane protocol or a data plane protocol, and wherein the trace information is analyzed to detect cross-slice message delivery.

9 . The apparatus of claim 8 , wherein generating the analytics information comprises combining a preliminary isolation analysis performed by the Network Data Analytics Function (NWDAF) in a core domain with end-to-end analytics performed by the Management Data Analytics Function (MDAF) across multiple management domains.

10 . The apparatus of claim 9 , wherein generating the analytics information further comprises triggering, during runtime, an automated mitigation action responsive to detection of an isolation policy violation.

11 . The apparatus of claim 10 , wherein correlating the data further comprises determining that a degradation in network slice performance metrics is associated with one or more detected S-NSSAI mismatches.