Guardian Orchestrator Automates VNF Security in NFV MANO
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security mechanisms for Virtualized Network Functions (VNFs) in cloud environments are poorly integrated into Network Function Virtualization Management and Orchestration (NFV MANO) infrastructure, requiring heavy operator interaction and lacking effective orchestration for security protection.
Innovation Solution
The introduction of a Guardian Orchestrator (GOrch) that obtains security orchestration information, determines relevant network interfaces based on topology, and issues security instructions to protect VNFs, including activating or deactivating protector VNFs, thereby enhancing security orchestration and protection within the NFV MANO structure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security mechanisms are implemented for VNFs, then security protection is improved, but integration with NFV MANO infrastructure deteriorates (remains poor)
Solution Approach 1:
The patent merges security mechanisms with the NFV MANO infrastructure by integrating security orchestration, monitoring, and management functions directly into the existing virtualization management framework. This allows security protection to be implemented without creating separate ad-hoc systems, thereby improving both security reliability and integration coherence.
Solution Approach 2:
The security mechanisms are designed to be universal and compatible across different VNF types and NFV MANO implementations. By creating a standardized security layer that can work with various virtualized network functions and management systems, the patent improves security protection while avoiding the complexity of custom integrations for each specific case.
2Reliability
If ad-hoc security solutions are used, then security protection is provided, but operator interaction complexity increases (requiring heavy interaction)
Solution Approach 1:
The security mechanisms are designed to operate autonomously with minimal operator intervention. The system automatically monitors VNFs, detects security violations, and executes protection actions without requiring heavy operator interaction, thereby maintaining security protection while significantly improving ease of operation.
Solution Approach 2:
The patent implements continuous monitoring and feedback loops that automatically detect security conditions and trigger appropriate protection measures. This closed-loop system eliminates the need for manual operator intervention by providing real-time feedback and automated response, thus improving ease of operation while maintaining reliable security protection.
3Reliability
If manual security management is used, then security protection is provided, but automation level deteriorates (lacking orchestration)
Solution Approach 1:
The patent implements preliminary security orchestration by pre-configuring security policies, protection mechanisms, and response procedures before security incidents occur. This automated framework is ready to execute immediately when threats are detected, providing reliable security protection while maintaining high automation levels without manual intervention.
Solution Approach 2:
The patent introduces an automated security orchestration layer that acts as an intermediary between security monitoring functions and protection execution mechanisms. This intermediary automatically coordinates security actions across multiple VNFs and systems, thereby improving the extent of automation while maintaining reliable security protection through centralized orchestration.
Data Source
AI summary
A method for protection of virtualized network functions may comprise: obtaining security orchestration information for one or more virtualized network functions; determining network interfaces relevant to protection of the one or more virtualized network functions based at least in part on network topology information, in response to the security orchestration information; and issuing a security instruction for the protection of the one or more virtualized network functions, according to the determined network interfaces.

