Guardian Orchestrator Automates VNF Security in NFV MANO

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security mechanisms for Virtualized Network Functions (VNFs) in cloud environments are poorly integrated into Network Function Virtualization Management and Orchestration (NFV MANO) infrastructure, requiring heavy operator interaction and lacking effective orchestration for security protection.

Innovation Solution

The introduction of a Guardian Orchestrator (GOrch) that obtains security orchestration information, determines relevant network interfaces based on topology, and issues security instructions to protect VNFs, including activating or deactivating protector VNFs, thereby enhancing security orchestration and protection within the NFV MANO structure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security mechanisms are implemented for VNFs, then security protection is improved, but integration with NFV MANO infrastructure deteriorates (remains poor)

Engineering Contradiction:
Improvesecurity protectionVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security mechanisms with the NFV MANO infrastructure by integrating security orchestration, monitoring, and management functions directly into the existing virtualization management framework. This allows security protection to be implemented without creating separate ad-hoc systems, thereby improving both security reliability and integration coherence.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security mechanisms are designed to be universal and compatible across different VNF types and NFV MANO implementations. By creating a standardized security layer that can work with various virtualized network functions and management systems, the patent improves security protection while avoiding the complexity of custom integrations for each specific case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If ad-hoc security solutions are used, then security protection is provided, but operator interaction complexity increases (requiring heavy interaction)

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperator interaction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security mechanisms are designed to operate autonomously with minimal operator intervention. The system automatically monitors VNFs, detects security violations, and executes protection actions without requiring heavy operator interaction, thereby maintaining security protection while significantly improving ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements continuous monitoring and feedback loops that automatically detect security conditions and trigger appropriate protection measures. This closed-loop system eliminates the need for manual operator intervention by providing real-time feedback and automated response, thus improving ease of operation while maintaining reliable security protection.

Inventive Principle:
Principle #23Feedback

3Reliability

If manual security management is used, then security protection is provided, but automation level deteriorates (lacking orchestration)

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity orchestration
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements preliminary security orchestration by pre-configuring security policies, protection mechanisms, and response procedures before security incidents occur. This automated framework is ready to execute immediately when threats are detected, providing reliable security protection while maintaining high automation levels without manual intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an automated security orchestration layer that acts as an intermediary between security monitoring functions and protection execution mechanisms. This intermediary automatically coordinates security actions across multiple VNFs and systems, thereby improving the extent of automation while maintaining reliable security protection through centralized orchestration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11165829B2Virtualized network function security wrapping orchestration in the cloud environment
Publication Date: 2021.11.02 NOKIA TECHNOLOGIES OY
  • US11165829B2 patent drawing
  • US11165829B2 patent drawing

AI summary

A method for protection of virtualized network functions may comprise: obtaining security orchestration information for one or more virtualized network functions; determining network interfaces relevant to protection of the one or more virtualized network functions based at least in part on network topology information, in response to the security orchestration information; and issuing a security instruction for the protection of the one or more virtualized network functions, according to the determined network interfaces.