DNSSEC VNF Image Verification Across Container Platforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The deployment and validation of virtual network function (VNF) signatures in network systems are complex due to proprietary verification mechanisms, different formats, and the need for third-party integration, which complicates standardization and increases maintenance efforts.
Innovation Solution
Utilize Domain Name System Security Extensions (DNSSEC) for standardized signature management, leveraging DNS infrastructure to validate signatures provided by third parties, ensuring compatibility across different systems and reducing maintenance costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary verification mechanisms are used for VNF signature validation, then system-specific security requirements are met, but device complexity and maintenance difficulty increase
Solution Approach 1:
The patent applies universality by implementing a standardized signature verification mechanism that works across multiple VNF platforms and container orchestration systems. The DNSSEC-based verification process provides a common framework that can validate signatures from different vendors and systems, replacing proprietary mechanisms with a universal standard that maintains security while reducing complexity.
Solution Approach 2:
The patent changes the verification parameter from proprietary binary formats to standardized DNSSEC record types (RRSIG, DNSKEY, DS). By transforming the signature verification into DNS protocol operations with standardized record structures, the system achieves platform-independent validation while simplifying the verification process through consistent parameter handling.
2Reliability
If third-party vendor signatures are integrated into the system, then VNF authenticity is verified, but adaptation effort and integration complexity increase
Solution Approach 1:
The patent introduces DNSSEC as an intermediary layer between VNF vendors and container orchestration systems. The DNSSEC infrastructure acts as a mediator that standardizes signature verification, allowing third-party vendor signatures to be validated through a common protocol without requiring direct integration between each vendor and every platform, thus improving adaptability while maintaining authenticity verification.
Solution Approach 2:
The patent segments the signature verification process into independent DNSSEC resolution steps (DNSKEY retrieval, RRSIG validation, chain of trust verification). This segmentation allows each step to be handled independently through standardized DNS queries, making the system more adaptable to different vendors and platforms while maintaining rigorous authenticity verification.
3Adaptability or versatility
If standardized signature formats are implemented across systems, then interoperability improves, but integration effort with existing proprietary systems increases
Solution Approach 1:
The patent implements self-service by allowing the DNSSEC infrastructure to automatically perform signature validation without requiring manual configuration or adaptation in each system. The standardized DNSSEC records and verification process enable systems to independently validate VNF signatures through automated DNS queries, improving interoperability while reducing implementation effort through automation.
4Reliability
If multiple signature verification procedures are maintained for different platforms, then platform-specific requirements are met, but maintenance costs and time increase
Solution Approach 1:
The patent applies universality by creating a single standardized DNSSEC verification procedure that serves multiple platforms simultaneously. The same DNSSEC resolution process and validation logic can verify signatures across different container orchestration systems and VNF platforms, eliminating the need to maintain separate verification procedures while preserving platform-specific verification accuracy through standardized protocols.
Data Source
AI summary
A method, system and apparatus are disclosed. According to one or more embodiments, a verifier is provided. The verifier includes processing circuitry configured to obtain a hash algorithm and a fully qualified domain name, FQDN, associated with a virtual network function, VNF, image, determine an identifier for the VNF image based at least on the hash algorithm and the FQDN, perform domain name system security extensions, DNSSEC, resolution of the determined identifier for the VNF image at least in part by requesting at least one attribute of the VNF image using the determined identifier for the VNF image and validating a response associated with the request, and perform validation of the VNF image in response to successful DNSSEC resolution.


