Hardware Trusted MANO Validation for NFV Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network Function Virtualization (NFV) infrastructures lack efficient and effective access to hardware trusted Management and Orchestration (MANO) systems, particularly when hosted on different computer hardware, which compromises the security and reliability of data communication services.

Innovation Solution

Implementing a hardware trusted MANO system where a Hardware (HW) trust server issues challenges, validates HW trust results, and distributes certificates to MANO systems, ensuring only trusted hardware is used for data communication, thereby isolating untrusted systems and maintaining secure data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware trust validation is implemented across NFV infrastructures, then security and reliability of data communication services are improved, but system complexity and difficulty of hardware verification increase

Engineering Contradiction:
Improvesecurity and reliability of data communication servicesVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Hardware Trust Server as an intermediary component that mediates between NFV infrastructures and the hardware trust validation process. This server maintains a database of valid hardware trust keys and coordinates the verification process, thereby centralizing the complexity of hardware trust management and preventing it from propagating throughout the entire NFV system. The intermediary handles the complex tasks of key management and validation coordination, allowing other components to interact through simplified interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where the Hardware Trust Server provides validation results back to NFV infrastructures. When hardware trust is validated, the system receives confirmation feedback that enables secure operations. This feedback loop allows the system to dynamically adjust its security posture based on validation outcomes, maintaining reliability while managing complexity through structured information flow rather than hard-coded complex validation logic throughout the system.

Inventive Principle:
Principle #23Feedback

2Reliability

If hardware trust validation is implemented across NFV infrastructures, then security and reliability of data communication services are improved, but the difficulty of detecting and measuring hardware identity increases

Engineering Contradiction:
Improvesecurity and reliability of data communication servicesVSAvoiddifficulty of detecting and measuring hardware identity
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts the hardware identity detection and measurement functions into a dedicated Hardware Trust Server that specializes in this task. Instead of distributing complex hardware detection capabilities across all NFV components, the system extracts this functionality into a single centralized service that handles all hardware trust key validations. This extraction reduces the difficulty of hardware identity detection for individual components while maintaining high security through specialized hardware verification expertise in one location.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The Hardware Trust Server acts as an intermediary that simplifies hardware identity detection for NFV infrastructures. Rather than requiring each NFV component to directly detect and measure hardware identities, the intermediary server handles these complex detection and measurement tasks centrally, using specialized protocols and databases to verify hardware trust keys. This mediation reduces the technical difficulty for individual components while maintaining rigorous security validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If MANO systems are hosted on different computer hardware, then system versatility and scalability are improved, but access efficiency and effectiveness to hardware trusted MANO systems deteriorates

Engineering Contradiction:
Improvesystem versatilityVSAvoidaccess efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements a universal Hardware Trust Server that serves multiple NFV infrastructures and MANO systems hosted on different hardware platforms. This single server provides hardware trust validation services to diverse systems, enabling them to all access trusted MANO functions through a common interface. The universal server maintains databases of hardware trust keys for multiple systems, allowing versatile deployment across different hardware while providing efficient centralized access rather than requiring each system to implement its own trust validation infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The Hardware Trust Server serves as an intermediary that enables efficient access to hardware trusted MANO systems across different hardware platforms. Instead of requiring direct peer-to-peer trust validation between distributed MANO systems, the intermediary server coordinates access requests, validates hardware identities centrally, and manages trust relationships. This mediation improves access efficiency by consolidating validation operations and providing a standardized access path for all MANO systems regardless of their underlying hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enables secure and efficient access to hardware trusted MANO systems, ensuring robust and reliable data communication services by validating hardware trust across NFV infrastructures, allowing trusted MANO systems to exchange user data securely and reliably.

Implementation Method 1

The first MANO system hashes its physically-embedded read-only hardware trust key to generate a HW trust result and transfers the HW trust result to the HW trust server. The HW trust server validates the hardware trust result

Methodology Applied
Scientific EffectHashing:

Data Source

PatentUS11057203B2Network Function Virtualization (NFV) hardware trusted hosted MANO
Publication Date: 2021.07.06 T MOBILE INNOVATIONS LLC
  • US11057203B2 patent drawing
  • US11057203B2 patent drawing
  • US11057203B2 patent drawing

AI summary

A Network Function Virtualization (NFV) system implements hardware trusted Management and Orchestration (MANO). A Hardware (HW) trust server issues a HW trust challenge to a first MANO system. The first MANO system hashes its physically-embedded read-only hardware trust key to generate a HW trust result and transfers the HW trust result to the HW trust server. The HW trust server validates the hardware trust result and transfers a HW trust certificate to the first MANO system. The first MANO system transfers the HW trust certificate and NFV MANO data to a second MANO system. The second MANO system validates the HW trust certificate. The second MANO system exchanges NFVI control data with NFVI circuitry responsive to the NFV MANO data when the HW trust certificate is valid. The second MANO system isolates the NFV MANO data when the HW trust certificate is not valid.