Dynamic Trust Attributes for Virtualized Network Function Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized telco networks, there is a need for reliable mechanisms to identify and authorize Virtualized Network Functions (VNF) instances securely, especially considering their dynamic nature, such as instantiation, migration, and termination, where traditional trust mechanisms based on static identities and physical uniqueness are inadequate.

Innovation Solution

The introduction of unique trust attributes generated and assigned to each VNF instance during instantiation, which are cryptographically secured and managed by a security management entity, ensuring dynamic trust management and authorization, and are invalidated upon instance termination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional trust mechanisms based on static identities and physical uniqueness are used, then simplicity of implementation is maintained, but reliability of security identification deteriorates in dynamic virtualized environments

Engineering Contradiction:
Improvesecurity identification reliabilityVSAvoidtrust mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic trust attributes that are generated and assigned to each VNF instance during instantiation, allowing the trust mechanism to adapt to the dynamic nature of virtualized networks where VNFs are created, migrated, and terminated frequently. This dynamic approach ensures that each instance has a unique, time-bound trust attribute that reflects its current state, resolving the contradiction between reliability in dynamic environments and implementation simplicity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of trust from static identity to dynamic attributes including unique identifiers, cryptographic keys, and validity periods. These parameters are generated anew for each VNF instance and updated throughout the instance lifecycle, enabling reliable security identification in virtualized environments while managing complexity through systematic parameter management.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If unique trust attributes are generated and assigned to each VNF instance during instantiation, then reliability of authorization is improved, but device complexity increases due to cryptographic management

Engineering Contradiction:
Improveauthorization reliabilityVSAvoidcryptographic management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary cryptographic setup during the VNF instantiation process, where unique trust attributes including key pairs are generated and assigned before the VNF begins operation. This preliminary action ensures that authorization reliability is established from the outset, while the complexity of cryptographic management is handled systematically during the initialization phase rather than during ongoing operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables VNF instances to self-configure with their own unique trust attributes during instantiation, with the security management entity providing the necessary cryptographic materials. This self-service approach improves authorization reliability by ensuring each instance has its own dedicated credentials, while reducing the operational burden of manual cryptographic management.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If trust attributes are invalidated upon instance termination, then security against unauthorized actions is improved, but loss of time occurs during attribute management

Engineering Contradiction:
Improveunauthorized actions preventionVSAvoidattribute management time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements preliminary anti-action by establishing validity periods and termination conditions for trust attributes in advance. When a VNF instance is terminated, the associated trust attributes are automatically invalidated according to pre-defined rules, preventing unauthorized actions by ensuring that credentials expire with the instance. This automated invalidation process minimizes manual intervention time while maintaining strong security.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3443500B1Security in virtualized networks
Publication Date: 2022.04.27 NOKIA TECHNOLOGIES OY
  • EP3443500B1 patent drawingFigure 1
  • EP3443500B1 patent drawingFigure 2
  • EP3443500B1 patent drawingFigure 3

AI summary

A method for security in a virtualized network comprising: generating an attribute for a virtualised component in a virtualised environment, the attribute being generated so as to be unique to the virtualised component; assigning the attribute to the virtualised component; the attribute comprising a trust attribute.