Hardware Trusted MANO Validation for NFV Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network Function Virtualization (NFV) infrastructures lack efficient and effective access to hardware trusted Management and Orchestration (MANO) systems, particularly when hosted on different computer hardware, which compromises the security and reliability of data communication services.
Innovation Solution
Implementing a hardware trusted MANO system where a Hardware (HW) trust server issues challenges, validates HW trust results, and distributes certificates to MANO systems, ensuring only trusted hardware is used for data communication, thereby isolating untrusted systems and maintaining secure data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware trust validation is implemented across NFV infrastructures, then security and reliability of data communication services are improved, but system complexity and difficulty of hardware verification increase
Solution Approach 1:
The patent introduces a Hardware Trust Server as an intermediary component that mediates between NFV infrastructures and the hardware trust validation process. This server maintains a database of valid hardware trust keys and coordinates the verification process, thereby centralizing the complexity of hardware trust management and preventing it from propagating throughout the entire NFV system. The intermediary handles the complex tasks of key management and validation coordination, allowing other components to interact through simplified interfaces.
Solution Approach 2:
The system implements a feedback mechanism where the Hardware Trust Server provides validation results back to NFV infrastructures. When hardware trust is validated, the system receives confirmation feedback that enables secure operations. This feedback loop allows the system to dynamically adjust its security posture based on validation outcomes, maintaining reliability while managing complexity through structured information flow rather than hard-coded complex validation logic throughout the system.
2Reliability
If hardware trust validation is implemented across NFV infrastructures, then security and reliability of data communication services are improved, but the difficulty of detecting and measuring hardware identity increases
Solution Approach 1:
The patent extracts the hardware identity detection and measurement functions into a dedicated Hardware Trust Server that specializes in this task. Instead of distributing complex hardware detection capabilities across all NFV components, the system extracts this functionality into a single centralized service that handles all hardware trust key validations. This extraction reduces the difficulty of hardware identity detection for individual components while maintaining high security through specialized hardware verification expertise in one location.
Solution Approach 2:
The Hardware Trust Server acts as an intermediary that simplifies hardware identity detection for NFV infrastructures. Rather than requiring each NFV component to directly detect and measure hardware identities, the intermediary server handles these complex detection and measurement tasks centrally, using specialized protocols and databases to verify hardware trust keys. This mediation reduces the technical difficulty for individual components while maintaining rigorous security validation.
3Adaptability or versatility
If MANO systems are hosted on different computer hardware, then system versatility and scalability are improved, but access efficiency and effectiveness to hardware trusted MANO systems deteriorates
Solution Approach 1:
The patent implements a universal Hardware Trust Server that serves multiple NFV infrastructures and MANO systems hosted on different hardware platforms. This single server provides hardware trust validation services to diverse systems, enabling them to all access trusted MANO functions through a common interface. The universal server maintains databases of hardware trust keys for multiple systems, allowing versatile deployment across different hardware while providing efficient centralized access rather than requiring each system to implement its own trust validation infrastructure.
Solution Approach 2:
The Hardware Trust Server serves as an intermediary that enables efficient access to hardware trusted MANO systems across different hardware platforms. Instead of requiring direct peer-to-peer trust validation between distributed MANO systems, the intermediary server coordinates access requests, validates hardware identities centrally, and manages trust relationships. This mediation improves access efficiency by consolidating validation operations and providing a standardized access path for all MANO systems regardless of their underlying hardware.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution enables secure and efficient access to hardware trusted MANO systems, ensuring robust and reliable data communication services by validating hardware trust across NFV infrastructures, allowing trusted MANO systems to exchange user data securely and reliably.
Implementation Method 1
The first MANO system hashes its physically-embedded read-only hardware trust key to generate a HW trust result and transfers the HW trust result to the HW trust server. The HW trust server validates the hardware trust result
Data Source
AI summary
A Network Function Virtualization (NFV) system implements hardware trusted Management and Orchestration (MANO). A Hardware (HW) trust server issues a HW trust challenge to a first MANO system. The first MANO system hashes its physically-embedded read-only hardware trust key to generate a HW trust result and transfers the HW trust result to the HW trust server. The HW trust server validates the hardware trust result and transfers a HW trust certificate to the first MANO system. The first MANO system transfers the HW trust certificate and NFV MANO data to a second MANO system. The second MANO system validates the HW trust certificate. The second MANO system exchanges NFVI control data with NFVI circuitry responsive to the NFV MANO data when the HW trust certificate is valid. The second MANO system isolates the NFV MANO data when the HW trust certificate is not valid.


