Blockchain VNF Integrity Verification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for verifying the integrity of Virtual Network Functions (VNFs) in Network Function Virtualization (NFV) are limited, lacking robustness against unauthorized changes and relying on central databases that are vulnerable to hacking attacks.

Innovation Solution

A system that computes a unique identifier for VNF packages or network service definitions, stores it in a blockchain or shared database, and allows entities to verify integrity using this identifier, ensuring immutability and security against tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a centralized database is used to store VNF integrity identifiers, then verification efficiency is improved, but security against hacking attacks deteriorates

Engineering Contradiction:
Improveverification efficiencyVSAvoidsecurity against hacking attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the centralized verification authority into multiple distributed nodes forming a blockchain network. Each node maintains a copy of the integrity identifiers, eliminating the single point of failure while preserving verification efficiency through parallel access to distributed ledger data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces blockchain technology as an intermediary layer between VNF storage and verification systems. This intermediary provides cryptographic proof of integrity without requiring trust in any single entity, simultaneously improving security while maintaining verification speed through optimized consensus mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If blockchain technology is used to store VNF integrity identifiers, then security against tampering is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against tamperingVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex blockchain consensus and validation logic into a separate, specialized module. This allows the main VNF verification system to remain simple while delegating security-critical functions to the blockchain subsystem, reducing overall system complexity while maintaining high security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary computation of integrity identifiers (hashes) during VNF packaging and storage in the blockchain. This preliminary action eliminates the need for complex real-time verification computations, simplifying the operational complexity of the verification system while maintaining strong security guarantees.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If current verification techniques are used, then ease of operation is maintained, but robustness against unauthorized changes deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidrobustness against unauthorized changes
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates cryptographic copies (hashes) of VNF integrity identifiers and stores them in the blockchain. These cryptographic copies serve as immutable references that can be verified without accessing the original VNF data, maintaining operational simplicity while providing strong robustness against unauthorized modifications.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11271948B2System, method, and computer program for verifying virtual network function (VNF) package and/or network service definition integrity
Publication Date: 2022.03.08 AMDOCS DEV LTD
  • US11271948B2 patent drawing
  • US11271948B2 patent drawing
  • US11271948B2 patent drawing

AI summary

A system, method, and computer program product are provided for verifying virtual network function (VNF) package and/or network service definition integrity. In use, a system identifies a virtual network function package or a network service definition for performing integrity verification. The system computes a unique identifier of the VNF package or the network service definition that allows verification of an integrity of the VNF package or the network service definition. The system stores the unique identifier in a blockchain or a shared database. The system provides the VNF package or the network service definition to an entity such that the entity is capable of verifying the integrity of the VNF package or the network service definition by using the unique identifier of the VNF package or the network service definition from the blockchain or the shared database.