DNSSEC VNF Image Verification Across Container Platforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment and validation of virtual network function (VNF) signatures in network systems are complex due to proprietary verification mechanisms, different formats, and the need for third-party integration, which complicates standardization and increases maintenance efforts.

Innovation Solution

Utilize Domain Name System Security Extensions (DNSSEC) for standardized signature management, leveraging DNS infrastructure to validate signatures provided by third parties, ensuring compatibility across different systems and reducing maintenance costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary verification mechanisms are used for VNF signature validation, then system-specific security requirements are met, but device complexity and maintenance difficulty increase

Engineering Contradiction:
Improvesignature verification reliabilityVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by implementing a standardized signature verification mechanism that works across multiple VNF platforms and container orchestration systems. The DNSSEC-based verification process provides a common framework that can validate signatures from different vendors and systems, replacing proprietary mechanisms with a universal standard that maintains security while reducing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the verification parameter from proprietary binary formats to standardized DNSSEC record types (RRSIG, DNSKEY, DS). By transforming the signature verification into DNS protocol operations with standardized record structures, the system achieves platform-independent validation while simplifying the verification process through consistent parameter handling.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If third-party vendor signatures are integrated into the system, then VNF authenticity is verified, but adaptation effort and integration complexity increase

Engineering Contradiction:
ImproveVNF authenticity verificationVSAvoidplatform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces DNSSEC as an intermediary layer between VNF vendors and container orchestration systems. The DNSSEC infrastructure acts as a mediator that standardizes signature verification, allowing third-party vendor signatures to be validated through a common protocol without requiring direct integration between each vendor and every platform, thus improving adaptability while maintaining authenticity verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the signature verification process into independent DNSSEC resolution steps (DNSKEY retrieval, RRSIG validation, chain of trust verification). This segmentation allows each step to be handled independently through standardized DNS queries, making the system more adaptable to different vendors and platforms while maintaining rigorous authenticity verification.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If standardized signature formats are implemented across systems, then interoperability improves, but integration effort with existing proprietary systems increases

Engineering Contradiction:
Improvesystem interoperabilityVSAvoidimplementation effort
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements self-service by allowing the DNSSEC infrastructure to automatically perform signature validation without requiring manual configuration or adaptation in each system. The standardized DNSSEC records and verification process enable systems to independently validate VNF signatures through automated DNS queries, improving interoperability while reducing implementation effort through automation.

Inventive Principle:
Principle #25Self-service

4Reliability

If multiple signature verification procedures are maintained for different platforms, then platform-specific requirements are met, but maintenance costs and time increase

Engineering Contradiction:
Improveplatform-specific verification accuracyVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies universality by creating a single standardized DNSSEC verification procedure that serves multiple platforms simultaneously. The same DNSSEC resolution process and validation logic can verify signatures across different container orchestration systems and VNF platforms, eliminating the need to maintain separate verification procedures while preserving platform-specific verification accuracy through standardized protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12413597B2Domain name system security extension (DNSSEC) for container signature management
Publication Date: 2025.09.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12413597B2 patent drawing
  • US12413597B2 patent drawing
  • US12413597B2 patent drawing

AI summary

A method, system and apparatus are disclosed. According to one or more embodiments, a verifier is provided. The verifier includes processing circuitry configured to obtain a hash algorithm and a fully qualified domain name, FQDN, associated with a virtual network function, VNF, image, determine an identifier for the VNF image based at least on the hash algorithm and the FQDN, perform domain name system security extensions, DNSSEC, resolution of the determined identifier for the VNF image at least in part by requesting at least one attribute of the VNF image using the determined identifier for the VNF image and validating a response associated with the request, and perform validation of the VNF image in response to successful DNSSEC resolution.