| As a key technology in the fifth-generation mobile network(5G),the network slice logically divides the physical network,to satisfy different businesses for wireless devices and vertical industries connection demands.Cloud-native technology has rapidly developed in the cloud computing industry.cloud-native is expected to become the best choice for the 5G network slice "deploy to the cloud".Compared with the traditional virtualization technology,cloud-native technology can improve the utilization efficiency of underlying resources and reduce the cost of network slice operation,maintenance,management,and satisfy the elastic deployment,dynamic orchestration demands.This paper mainly researches 5G network slice orchestration for Cloud-Native.This paper proposed a 5G network slice management architecture.Based on this architecture,This paper designed network isolation technology based on SDN control plug-in and proposed an auction-based system to allocate cloud-native resources for network slices,which improve the overall benefits of network slicing business,while ensuring network security isolation of slicing business and providing ondemand resource isolation.For the requirements of rapid iteration,on-demand orchestrate of the virtual network function in network slice,this paper proposed the network slicing management architecture based on cloud-native technology,and manage the slicing life cycle and resource scheduling based on the network slicing instance(NSI)operator,meeting the automatic operation and maintenance requirements of slice business.This paper analyzes the potential security risks caused by isolation failure between slices;According to the security isolation requirements of network slice in the virtualized network environment,this paper implemented the OpenContrail container network plug-in to design the SDN-based network for cloud-native network slice.This paper can provide the network virtualization technology of multi-protocol label switching layer 3 virtual private network(MPLS 13VPN)tunnel to realize the network isolation between slices.The NSI Operator can orchestrate the OpenContrail controller to provide a fine-grained network policy for network functions of network slices.The experimental results show that the proposed scheme can meet the on-demand network isolation between slices,network isolation between container instances,and container communication between slices.To satisfy the requirements of on-demand isolation and maximize benefits in the resource management process of network slicing service in the virtualization environment,a cloud-native network slicing resource allocation mechanism based on an auction game is proposed.According to the Vickrey-Clarke-groves(VCG)auction mechanism,virtualization resources with different Service Level Agreement(SLA)levels are allocated to the slicing service.The proposed mechanism maximizes social warfare,meets the bidders’ individual rationality of slices.The experimental results show that the proposed scheme can on-demand resource isolation,ensure virtualization resource allocation efficiency. |