Chu
360
support multi‐tenancy in the infrastructure, so that the same infrastructure can be
provided to more than one consumer in a shared fashion. For the consumers, this is
functionality provided to them as a service (XaaS). They can build higher‐layer applications on top of the XaaS interface.
Let us take an example of IaaS (infrastructure as a service) where the provider operator offers its data center infrastructure to partners. The infrastructure is NFVI and VIM
in NFV terminology and it supports multi‐tenancy. The provider who may own the
infrastructure and the operation of it offers the use of this infrastructure in a cloud
fashion. NFVI consists of the virtualized assets being shared, and VIM provides the
interface or API so that the partners can consume this service. Multi‐tenancy means the
provider allows the partner/consumer to slice a virtual pool of computing resources
under the partner’s administrative control; the partner can virtually construct its own
network services, composed of VNFs, within its slice of resources. Consumers of
Amazon Web Services will be familiar with this consumption model; NFV extends this
to telco services.
Multi‐tenancy requires not only an efficient way of slicing the resources, but also
security and privacy protections offered by the provider to its partners/consumers.
Virtual private networks and their associated security rules, as described in the last
section, are the basic foundation. But additional capabilities are required, including
virtualization of supporting functions such as DNS, DHCP, identity, monitoring and
reporting. Moreover, additional services are required for virtual gateway routing so that
the virtual private network can securely connect with the Internet. We will often see that
software originally developed for private use, even private cloud use, cannot adequately
support these multi‐tenancy requirements.
The provider may optionally support more features for its partners or consumers.
These can be common tools that are needed to develop or deploy VNFs, such as
performance monitoring and reporting, logging, data analytics, enhanced security
services, databases, high availability, scaling and billing. These are often referred to as
either Platform as a Service (PaaS) or Software as a Services (SaaS), depending on how
we classify them into middle‐ware or application categories. All these services will
also need to support multi‐tenancy.
With 5G networks and applications, this concept of resource‐sharing and multi‐
tenancy are being pushed to new levels to include network‐sharing. For instance, a new
class of end‐user devices (say, IoT or healthcare or automobiles) can be supported with
a virtual slice of wireless access. Associated with each class is a slice of access network
infrastructure (virtual networks), and a slice of virtual computing infrastructure and
service applications (NFV data centers and VNFs). Each such class of services can have
its own capacity, its own security policy, its own SLA, billing and support models,
and so on.
15.6.4 OPNFV and Openstack: Open Source Projects for NFV
Why open source? Open source may seem like an off‐topic subject for 5G, security or
NFV, but it is not – for two very important reasons.
First, as we alluded to earlier, open source has been increasingly seen as an indispensable component in the development of NFV. The traditional standardization processes
made tremendous accomplishments in getting mobile networks to where we are today.
360
support multi‐tenancy in the infrastructure, so that the same infrastructure can be
provided to more than one consumer in a shared fashion. For the consumers, this is
functionality provided to them as a service (XaaS). They can build higher‐layer applications on top of the XaaS interface.
Let us take an example of IaaS (infrastructure as a service) where the provider operator offers its data center infrastructure to partners. The infrastructure is NFVI and VIM
in NFV terminology and it supports multi‐tenancy. The provider who may own the
infrastructure and the operation of it offers the use of this infrastructure in a cloud
fashion. NFVI consists of the virtualized assets being shared, and VIM provides the
interface or API so that the partners can consume this service. Multi‐tenancy means the
provider allows the partner/consumer to slice a virtual pool of computing resources
under the partner’s administrative control; the partner can virtually construct its own
network services, composed of VNFs, within its slice of resources. Consumers of
Amazon Web Services will be familiar with this consumption model; NFV extends this
to telco services.
Multi‐tenancy requires not only an efficient way of slicing the resources, but also
security and privacy protections offered by the provider to its partners/consumers.
Virtual private networks and their associated security rules, as described in the last
section, are the basic foundation. But additional capabilities are required, including
virtualization of supporting functions such as DNS, DHCP, identity, monitoring and
reporting. Moreover, additional services are required for virtual gateway routing so that
the virtual private network can securely connect with the Internet. We will often see that
software originally developed for private use, even private cloud use, cannot adequately
support these multi‐tenancy requirements.
The provider may optionally support more features for its partners or consumers.
These can be common tools that are needed to develop or deploy VNFs, such as
performance monitoring and reporting, logging, data analytics, enhanced security
services, databases, high availability, scaling and billing. These are often referred to as
either Platform as a Service (PaaS) or Software as a Services (SaaS), depending on how
we classify them into middle‐ware or application categories. All these services will
also need to support multi‐tenancy.
With 5G networks and applications, this concept of resource‐sharing and multi‐
tenancy are being pushed to new levels to include network‐sharing. For instance, a new
class of end‐user devices (say, IoT or healthcare or automobiles) can be supported with
a virtual slice of wireless access. Associated with each class is a slice of access network
infrastructure (virtual networks), and a slice of virtual computing infrastructure and
service applications (NFV data centers and VNFs). Each such class of services can have
its own capacity, its own security policy, its own SLA, billing and support models,
and so on.
15.6.4 OPNFV and Openstack: Open Source Projects for NFV
Why open source? Open source may seem like an off‐topic subject for 5G, security or
NFV, but it is not – for two very important reasons.
First, as we alluded to earlier, open source has been increasingly seen as an indispensable component in the development of NFV. The traditional standardization processes
made tremendous accomplishments in getting mobile networks to where we are today.
