IP/WDM Machine Hardware Root of Trust with NFV Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Optical communication networks have not integrated Hardware Root of Trust (HRoT), Network Function Virtualization (NFV), and Software-Defined Networks (SDN) systems, limiting their efficiency and effectiveness in secure and flexible data transfer.

Innovation Solution

An Internet Protocol/Wave Division Multiplex (IP/WDM) machine implements HRoT and NFV, using physically embedded keys for secure data processing and virtualization, and integrates with SDN for controlled data transfer over optical wavelengths, ensuring secure and efficient communication paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If optical networks transfer IP packets using dedicated optical fibers and wavelengths for VPNs, then network security and isolation are improved, but network flexibility and resource utilization deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the optical network into multiple virtual networks using wavelength division multiplexing, where each VPN is assigned dedicated wavelengths and optical fibers. This segmentation provides both security isolation (each VPN is physically separated) and flexibility (virtual networks can be dynamically created, modified, or deleted without affecting physical infrastructure).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal optical network infrastructure that can simultaneously support multiple VPNs with different security requirements and service types. The same physical optical fibers and switching equipment serve multiple virtual networks, providing both dedicated security paths and flexible resource allocation through software-controlled wavelength assignment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If HRoT systems maintain physical separation between trusted and untrusted hardware, then security is improved, but system complexity and integration difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces HRoT modules as intermediary trusted hardware components that mediate between untrusted network equipment and secure operations. These modules physically separate trusted key storage from untrusted processing hardware, yet enable integrated operation through secure interfaces and cryptographic protocols that allow the broader system to function as a unified whole.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent embeds HRoT trusted modules within larger network equipment systems, creating a nested architecture where secure key management functions are contained within protected hardware envelopes that are themselves integrated into untrusted network infrastructure. This nesting allows security functions to operate independently while maintaining system-level integration.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Productivity

If NFV systems run multiple virtual machines on shared hardware, then resource efficiency and capacity increase, but security isolation and control difficulties arise

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments virtual network functions across multiple isolated hardware platforms, where each NFV instance runs on dedicated physical or virtualized hardware with enforced isolation boundaries. This segmentation maintains high resource utilization through controlled sharing while ensuring security isolation through hardware-enforced separation of trusted and untrusted execution environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs HRoT modules as intermediary trust anchors that mediate between shared NFV infrastructure and security requirements. These modules verify the integrity of virtualized network functions and enforce security policies, allowing multiple VMs to share hardware resources efficiently while maintaining cryptographic proof of security isolation through remote attestation mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10050739B2Optical communication system with hardware root of trust (HRoT) and network function virtualization (NFV)
Publication Date: 2018.08.14 T MOBILE INNOVATIONS LLC
  • US10050739B2 patent drawing
  • US10050739B2 patent drawing
  • US10050739B2 patent drawing

AI summary

An Internet Protocol/Wave Division Multiplex (IP/WDM) machine implements Hardware Root of Trust (HRoT). In the IP/WDM machine, an IP router exchanges IP packets between IP ports and WDM interfaces based on IP control data. A WDM switch exchanges the IP packets between the WDM interfaces and WDM ports based on WDM control data. The WDM ports exchange the IP packets using different optical wavelengths. Data processing circuitry transfers HRoT data indicating the optical wavelengths used to exchange the IP packets and indicating an encoded hardware key that is physically-embedded in the IP/WDM machine.